On September 10, 2026, Anthropic published a threat intelligence report detailing how its AI chatbot Claude has been misused. Based on cases identified and disrupted between December 2025 and August 2026, the report covers misuse across seven areas, including cyberattacks, disinformation campaigns, fraud, and unauthorized use of Claude's outputs to train rival AI models, along with the company's response to each.
Nine Months of Cases Across Seven Harm Areas
The report covers cyber operations, influence operations, surveillance, scams and fraud, biological weapons-related activity, conventional weapons development, and unauthorized distillation of Claude's outputs by other companies. The actors involved reportedly range from suspected state-sponsored groups and financially motivated criminals to commercial spyware vendors, state propaganda organizations, and politically motivated individuals. Anthropic says that disclosing these patterns not only strengthens its own safeguards but also helps the wider industry defend against similar threats.
A Suspected Russia-Linked Cyberattack Group
Anthropic reports that a group whose activity is consistent with the known threat actor "Midnight Blizzard" used Claude in operations targeting government, diplomatic, and defense-related organizations in Ukraine and Europe. The group reportedly automated much of its attack workflow with AI, including modifying its tools and phishing infrastructure, and used AI agents to continuously rework its malware whenever it was flagged by security products, in an effort to evade detection. Anthropic says it shut down the activity as soon as it was discovered and used the findings to strengthen its safeguards.
Fake Dating Apps and Surveillance Tools
The report also describes a fraud network that used a series of fake dating apps to deceive users, as well as tooling built to continuously monitor specific individuals. In the influence operations category, one organization is said to have published roughly 9,000 articles across nearly 70 websites in 20 languages, amplifying them through around 250 fake social media accounts.
The report also highlights "distillation" — other companies harvesting large volumes of Claude's outputs to train their own models. Anthropic describes a campaign linked to Alibaba as the largest such operation it has ever measured, with more than 151 million exchanges observed between May and July 2026. According to the report, Claude was prompted to write out its full reasoning process, which was then collected and used as training data for Alibaba's Qwen model family. Separately, the report says Moonshot AI silently routed some customer requests to Claude and presented Claude's responses to users as if they came from its own Kimi model.
Summary
Anthropic states that simple keyword blocking and account suspensions are insufficient against organized, distributed threats, and is calling for stronger architectural safeguards, tighter API-level controls, real-time threat intelligence sharing among AI companies, and verified-access programs for sensitive research areas. The company says it disrupted each case covered in the report as soon as it was found and shared intelligence with authorities and industry partners where appropriate, and plans to continue publishing similar reports going forward.
