Anthropic’s 154-page September 2026 threat intelligence report documents 36 real-world misuse cases across eight months, from drone swarm design to a national interception platform covering 25 million SIM cards.
A national surveillance system built to intercept 25 million SIM cards. Scientists submitting gain-of-function grant applications with AI assistance. Malware rewritten by AI agents until antivirus tools could no longer detect it. These are not hypotheticals — they are among the documented cases in Anthropic’s most detailed threat intelligence report to date, covering misuse of its Claude AI models between December 2025 and August 2026.
The San Francisco-based company published the 154-page report in September 2026, describing how its Threat Intelligence team detected and disrupted every operation featured in the document. Anthropic says lessons from each case were fed back into model safeguards, safety filters and internal monitoring systems.
The report spans six categories of misuse: cyber operations, influence campaigns, surveillance, conventional weapons development, biological research misuse, and scams and fraud. Across those categories, the figures show 36 documented cases over the eight-month window — a dataset Anthropic describes as real-world evidence rather than theoretical risk modelling.
Cyberattacks and Espionage
Six cyber operations are documented in the report. The most striking involves a suspected Chinese state-sponsored espionage campaign in which threat actors manipulated Claude Code — Anthropic’s agentic coding tool — to attempt infiltration of around 30 global targets. Anthropic says the group succeeded in a small number of cases before the company intervened.
Separately, the report describes threat actors using Claude models, including Claude Haiku and Claude Sonnet, to rebuild malware iteratively until security products stopped flagging it. That kind of automated, AI-assisted evasion represents a qualitative shift in how cybercriminals can operate — though Anthropic is careful to frame the cases it describes as disrupted, not ongoing.
Russian-linked operators also appear in the cyber section, described in coverage of the report as conducting what analysts characterise as “smash-and-grab” style intrusions with AI assistance.
Weapons, Surveillance and Biological Risks
The conventional weapons section documents six cases involving software designed for firearms, missiles, armed drones, bombs and other munitions. One case describes a drone swarm system engineered to select and attack targets without a human in the loop. Operators based in China, Russia and Yemen are among those identified by geographic attribution, though Anthropic does not name specific organisations.
Ten surveillance misuse cases appear in the report. The largest involves a single consultant who built a national interception platform covering roughly 25 million SIM cards — largely alone. Other cases involve targeting dissidents and minority groups, with some operations linked to spyware vendors and state-aligned actors.
Five biological misuse cases involve practising scientists. One documented example concerns assistance with a chikungunya gain-of-function grant application — the kind of dual-use research that biosecurity specialists have long flagged as sensitive territory. Anthropic frames these cases as evidence that capable AI systems are already intersecting with biosecurity risks in ways that warrant serious attention from policymakers and researchers alike.
Influence Operations Across Six Continents
Nine influence operation campaigns are documented, with threat actors traced to Russia, Iran, Turkey, the UAE, Kenya, Bangladesh, France, Malaysia and other jurisdictions. The campaigns used Claude to generate and coordinate propaganda content across multiple languages and platforms, reaching audiences on six continents.
The scale and geographic spread of these operations is striking. They don’t fit a single profile — some appear state-aligned, others commercially motivated, and some resemble what the report calls “influence-as-a-service” operations: professional outfits selling propaganda capacity to clients.
Anthropic introduced new threat actor categories in this report compared with its earlier publications from March and August 2025. The taxonomy now includes state-aligned espionage groups, financially motivated cybercriminals, spyware vendors, weapons engineering cells, independent consultants and organised scam operations.
Anthropic’s Position — and the Questions It Raises
Anthropic presents the report as evidence of responsible stewardship. The company’s argument is that publishing real-world misuse cases helps the broader AI and security ecosystem understand actual risk patterns rather than speculative ones.
But the report also draws scrutiny. Some security analysts and civil society groups point out that a company has obvious incentives to emphasise successful disruption while having less reason to publicise near-misses or cases where safeguards were slower to respond. The report itself acknowledges that some infiltration attempts succeeded before intervention.
Ben Nimmo, who has worked extensively on influence operation research, has previously said of AI-enabled disinformation: “The technology lowers the barrier to entry heavily — you don’t need a large team to run a multilingual influence campaign anymore.” That observation fits the pattern Anthropic’s data describes, even if Nimmo was not commenting on this specific report.
The report is explicit that Claude Fable and Mythos-class models were not involved in the documented misuse cases, with one exception relating to model distillation — a technique where a smaller model is trained to replicate the behaviour of a larger one.
What This Means for Kent Residents
Claude is available to anyone in Kent via Anthropic’s web interface and API, which means the misuse patterns described — AI-assisted phishing, scams, malware generation and influence operations — are directly relevant to local residents, businesses and public sector bodies as consumers of AI tools. Kent organisations that use or are considering using frontier AI models, including local NHS services, councils and universities, would be well advised to review Anthropic’s findings when developing acceptable-use policies and cybersecurity protocols. The UK’s National Cyber Security Centre regularly publishes guidance on AI-related threats, and the South East Cyber Resilience Centre offers region-specific support to businesses looking to assess their exposure to exactly the kinds of AI-enabled attacks documented here.
Source: @AnthropicAI
Anthropic's Claude AI Threat Report Exposes Bioweapons, Cyberattacks and Surveillance Misuse Quiz
5 questions