Detecting and countering misuse of AI: September 2026 Anthropic's Threat Intelligence team disrupted malicious operations in which threat actors used Claude across seven harm areas between December 2025 and August 2026, according to the company's September 2026 misuse report. The actors included suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals, and the cases ranged from fake dating apps used to defraud users to surveillance systems built to monitor dissidents. Anthropic said the misuse involved Claude Haiku, Sonnet, and Opus models, with no cases involving Claude Fable or Mythos-class models except one illicit distillation case. Detecting and countering misuse of AI: September 2026 Related: Download report https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March https://www.anthropic.com/news/detecting-and-countering-malicious-uses-of-claude-march-2025 , August https://www.anthropic.com/news/detecting-countering-misuse-aug-2025 , and November https://www.anthropic.com/news/disrupting-AI-espionage 2025. In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate. This report covers activity we disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Claude Haiku, Sonnet, and Opus models were used. None of the misuse cases involved the use of Claude Fable or Mythos-class models, with the exception of one illicit distillation case. The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date. We’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer. The threat actors covered in this report include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals. The cases range from a network of fake dating apps designed to defraud users to surveillance systems built to identify and monitor dissidents. Sophisticated and persistent threat actors continuously test our safeguards and try to circumvent the technical measures we use to detect and prevent misuse. We’ll continue to evolve our safeguards and coordinate with our partners to improve our ability to detect, disrupt, and prevent future misuse. https://www.anthropic.com/news/building-safeguards-for-claude We hope that the findings in this report will help other developers recognize similar patterns on their own platforms, give governments and civil society a clearer view of how emerging threats take shape, and strengthen collective defenses. AI-augmented cyber operations Cyber operations: From assistant to orchestrator Over the past six months, our Threat Intelligence team identified and disrupted a series of cyber operations in which threat actors used Claude. The actors included suspected state-sponsored groups, financially motivated criminals, and politically motivated individuals. This section presents some of those cases. Throughout these case studies, the report will reference Generative Threat Groups GTGs . These are Anthropic’s internal designators for actors observed to be abusing AI. The report also attempts to measure uplift, a term we use to describe the AI capability boost, or how much more harm was caused with AI versus without AI. We view uplift through the lens of speed, scale, and depth, and attempt to determine how an actor’s adoption of AI meaningfully impacts each of these traits. Many commentators focus on the risk of AI developing exploits at scale. While this is a danger, the risk from AI adoption is more pronounced across the cyber kill chain, where adversaries can operate faster, across a broader and deeper surface area, with fewer resources. The cases span the period from December 2025 through August 2026. In all cases, Claude Haiku, Sonnet, and Opus models were used; no malicious activity was found on Claude Fable or Mythos which has a series of safeguards https://www.anthropic.com/news/fable-safeguards-jailbreak-framework in place that greatly reduce its ability to perform harmful cyber tasks . In each case we disrupted the activity involved, strengthened our AI safeguards based on what we learned, and shared intelligence with authorities and industry partners where appropriate. In the following report, we begin by discussing the key trends that we’ve observed in these cyber operations, then move to reporting the case studies and how they highlight those trends. Trends Sophisticated attacks no longer require sophisticated attackers The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators. In the case studies we report below, a hacktivist using stolen API keys, disparate financially motivated individuals, and a state espionage operator each sustained multi-victim campaigns that, even just a year ago, would have required many skilled operators and specialist knowledge. For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation. Every layer of offensive operations has been uplifted by AI, from reconnaissance and tool development to data processing and exploitation. An example of this uplift in capabilities is documented in case study GTG-50014 described below . The net effect of this uplift in capabilities is access to an increased breadth and depth of knowledge, which in turn drives increased speed of capability development and implementation. In November 2025, we documented an operating model used by a suspected state-sponsored campaign to carry out autonomous attacks. That operating model has now proliferated across every class of actors we investigated. Publicly available offensive agent frameworks, like PentAGI https://github.com/vxcontrol/pentagi , reproduce much of the same scaffolding for anyone who downloads them. This scaffolding effectively automates each step of the cyber kill chain. The operators behind observed cases range from state services to lone individuals, across a widening set of countries. An example of this adoption of AI-enabled kill chains is documented in case study GTG-20006. As models continue to evolve and improve, we assess that more actors, from lone wolves to organized entities, will continue to adopt AI frameworks to enable more sophisticated cyber attacks at greater speed and scale. AI’s role in cyber operations has become increasingly autonomous A majority of the operations described in this report were enabled by AI via direct execution or orchestration. The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration. Humans remained in the loop by setting the targets of attacks and reviewing exfiltration. An example of this trend is GTG-20006. This actor developed an AI-assisted workflow that automatically rebuilt and re-deployed their toolkit if it was detected by security products. GTG-20006: Russian espionage Historically, cyber espionage actors have followed a pattern of developing and deploying custom toolkits designed to evade detections. Actors would use these tools until defenders identified and built signatures to detect and block them, and there would then begin a new cycle of evasion and detection. Robust defenses and detections therefore created increased costs for adversaries. Now, however, the adoption of AI threatens to quickly and easily subvert defenders’ ability to impose costs on adversaries via static detections alone. GTG-20006 is an actor who has increased their speed by automating their operations using AI. Our attribution is consistent with public reporting linking the actor to Midnight Blizzard. One of the operators is a Russian speaker using the handle “JackPoterz” whose tradecraft and targeting are consistent with Russian state-nexus espionage. They ran operations attacking military intelligence targets in Ukrainian and European governments, as well as diplomatic and defense organizations and individuals connected to US foreign policy. We observed GTG-20006 operate through customized AI-driven workflows that automated much of their operations from development, infrastructure acquisition, phishing, persistence through command and control, to data exfiltration. GTG-20006 employed a custom toolkit composed of two families of Windows-based implants, a mobile exploitation kit, a credential stealing tool that targets browser password stores, a phishing platform designed to mimic priority targets like government organizations, and an administrative console used to manage compromised accounts. Each of these tools was managed and re-tooled as needed during the cyber operations through AI-assisted workflows. The actor also used AI to monitor how well their tools evaded detections from known security defenses. If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections. The agents were designed to continue iterating on GTG-20006’s toolkit until it was undetected. At that point, the tools were staged for live operations from disposable hosting servers where victim traffic was directed to retrieve the malware during their many cyber operations, including phishing, ClickFix https://en.wikipedia.org/wiki/ClickFix , and DNS hijacking schemes. The actor also used AI to drive their phishing operations. They developed AI-driven workflows to research then register domains and then configure the hosting infrastructure used to send phishing emails. Additional workflows were developed to send the emails and monitor the C2 channels for successful compromises. The human actor engaged primarily to modify Claude Code skills that drove the workflows when they needed to be refined. Our investigation identified more than 20 distinct organizations targeted in the actor’s operational planning, reconnaissance, and live operations. They included government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks, and defense-industrial companies, concentrated in Ukraine and Europe but extending to the Middle East and maritime related government agencies in Asia. A common theme of the targeting was Ukraine and military drone technology providers and supply chains. Exceptions included a Southeast Asian government entity relating to maritime shipping and tracking, and a North African government technology authority. Cyber operations The most commonly recurring targets were members of the Ukrainian government, military, and diplomatic staff. The actor scanned email services and remote access systems across more than two dozen Ukrainian government organizations. A secondary recurring target for theft was drone supply chain technology. The actor bulk-exported the mailboxes of at least two drone component manufacturers, targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system. They spent several days reverse-engineering the drone’s vision system, recovering its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product. Military drone control and AI vision-related firmware appeared to be of particular interest. Not all targets were direct: to reach their targets indirectly, the actor compromised at least three hospitality vendors that operate hotel guest WiFi. They used compromised admin credentials to modify DNS records so that they pointed to services owned by the actor a technique known as DNS hijacking . Guests of hotels using the compromised vendors who connected to the hotel WiFi had their traffic, device identifier and IP address sent to the actor’s servers. At that point, ClickFix https://en.wikipedia.org/wiki/ClickFix -style lures were staged to deliver Windows, Android and iOS malware to the victim’s device. The actor was able to use a combination of guest information stolen from the hotel management systems with the data stolen from individual guests’ devices to focus additional targeting efforts. Particular targets of interest were individuals associated with Ukraine, including government officials and drone manufacturers. Note that in July 2026, Microsoft Threat Intelligence published a report on the method of theft and malware delivery used here, which they referred to as CaptiveCrunch https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/ . The actor also took over victims’ WhatsApp accounts, using a platform of headless browsers https://en.wikipedia.org/wiki/Headless browser to link victim accounts as companion devices. In part by using the WPPConnect https://github.com/wppconnect-team/wppconnect open-source WhatsApp automation library, the actor’s configuration suppressed read receipts so victims would not notice while it bulk-exported Russian and Ukrainian language conversations. At least two former high-level Ukrainian officials were targeted in this way. The actor also targeted surveillance platforms. They found authorization flaws in the application interface of camera streaming services, and from there they enumerated users and harvested tokens that granted them access to the victims’ live camera streams. The same actor also conducted an intrusion of a North African government technology authority. They stole credentials to a VPN appliance, and used them to take over the organization’s central account server. This allowed them to exfiltrate its full credential database: more than 300,000 national identity records, and the commercial registry data of more than half a million companies operating in the country. The actor continued to develop a cloud email espionage platform that in part used “Embassy Kit,” the actor’s framework for managing device code phishing, to operate a Microsoft 365 token theft campaign. This platform, which was used to target diplomatic and government personnel, resulted in the access and exfiltration of mail records from at least eight organizations including a national prosecutor office, a military education institute, and a regional intergovernmental organization. Windows credential stealers were delivered via fake update-themed social engineering lures, alongside companion payloads with full remote access capabilities. These payloads were designed to freeze the victim machine’s security updates, meaning that new malware detection signatures published by security vendors would not be retrieved or run on the victim’s machine. The actor used AI at every point in their operations: - Reconnaissance: The actor used AI to fingerprint email and remote access systems and to harvest information from public sources, building target lists for phishing. - Initial access: The actor used AI to build and operate the platform that ran these cyber intrusion campaigns. The campaign’s primary access technique was a form of device code phishing that abused legitimate sign-in flows for cloud email services for further details on device code phishing see this post from Microsoft https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/ . The actor used AI to set up the phishing infrastructure and the exploitation tooling, and executed portions of the intrusions directly including running commands against victim systems, harvesting credentials, and moving laterally through networks under the actor’s direction. - Collection and exfiltration: The actor used AI to perform the extraction and organization of hundreds of gigabytes of stolen data. In some cases, exfiltration was achieved via bulk exports from compromised mailboxes. - Maintaining access: The actor used AI to assist in maintaining access to compromised accounts and tenants by automating the registration of actor-controlled devices into the victim organization’s tenant. In on-premises environments, the actor used AI to monitor the stealth and persistence of their implants. When their implants were flagged by security products, the actor used Claude to systematically identify, modify and redeploy the detected artifacts. The result of the above is that AI has inverted the cost back onto defenders. Previously, defenders might have been able to slow an attacker’s operational tempo via the deployment of a new detection. Now, at least in theory, capable adversaries can “close the loop,” bypassing traditional security detections faster than defenders can develop and deploy them. The actor’s malware included the following: - Windows malware: PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc; - Android malware: GiftDrop, a rebranded GiftsExpress Android surveillance RAT; - iOS malware: DarkSword, an iOS exploit chain. Indicators of compromise ms365-live . com teams.ms365-live . com m365-owa . com owa-ms365 . com ms365-device . com mslivetest.duckdns . org my-invite . org chamber-ua . org chathamhouse . eu ukrinform-share . net 104.145.210 . 184 31.57.243 . 154 statistic-ms . live static-ms . live 104.194.151 . 133 ad-g . org 104.194.159 . 55 docs-viewer . org 144.172.114 . 192 wa-connect . eu mygreatmarket . org mygreatmarket . com 213.145.86 . 112 2.26.53 . 194 cdncounter . net static.cdncounter . net stuseamandesilt . org api.stuseamandesilt . org cdn.stuseamandesilt . org update.stuseamandesilt . org itechx . tel pdfviewer2024.b-cdn . net meridian-protocol . org meridiangroup-corp . com projectnightcrawler . dev metricwave . org mgsend . org 148.135.195 . 111 185.198.234 . 26 185.198.234 . 101 149.54.42 . 106 104.194.149 . 228 38.146.28 . 132 38.146.28 . 75 wa-meeting . com russianearabroad . com russianearabroad . org anna.manager@russianearabroad . net events@embassy-protocol . int msedgeupdate v3 . exe msedgeupdate . exe version . dll WUEngine . exe DiagHost . exe client 20260507093021 4286d211 x64 . exe fix network . apk be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593 GTG-50014: ShinyHunters smash-and-grab opportunists While some cyber threat actors may conduct targeted intrusions, seeking specific information for espionage or other purposes, others are less focused and deliberate in their operations. These opportunistic hackers have historically used broad-based scanning techniques to identify and probe unpatched internet-facing systems, before exploiting these vulnerabilities to compromise or take over the target systems. We’ve identified several advanced threat actors who used AI to uplift their opportunistic criminal activity, using Claude’s capabilities to accelerate their ability to rapidly scan, exploit, and take over target systems. Opportunistic attacks come in many forms: racing N-day patches for mass exploitation; rummaging through public container stores, code repos, mobile applications, websites and more looking for credentials, tokens, and API keys; mass scan and exploitation of vulnerable internet facing devices; the creation of service accounts on novice service providers with poor security to escape their containers; prompt injection of LiteLLM or OpenClaw deployments; and more. Many actors scour the internet for ways into networks and services, stealing data for sale and extortion and later reselling access. This was the case before AI. With AI, however, the pre-existing ecosystem of criminal cyber conduct has increased in scale and severity. With AI, diverse target environments are made trivial to understand and adjust to; unique and obscure configurations are made clear and exploitable. The old adage of “security through obscurity” is no longer viable in this new AI-assisted world: everything connected to the internet is a potential target for exploitation. Once actors gain access, they typically move straight to databases and look for customer data. If the target is a software-as-a-service SaaS provider, they often use the stolen data to access the end customers, and make extortion demands, telling the provider that all of their data and their customers’ data will be leaked or sold online if they do not pay. We identified and disrupted multiple clusters of financially motivated cybercrime activity conducted by operators suspected to be affiliates of the ShinyHunters https://en.wikipedia.org/wiki/ShinyHunters collective, known for several large-scale data theft operations followed by pay-or-leak extortion demands. Although the affiliates appear disparate, and seem to be operating with their own tooling and operational workflows, analysis of their approaches and objectives shows that they are part of the same overall operation. One French-speaking operator going by the aliases of MeowSHA | frkoo | blazespider ran a distributed credential-harvesting pipeline across a fleet of 10 AWS EC2 workers. This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog https://github.com/trufflesecurity/trufflehog . Verified findings were routed in real time to a Telegram group organized into over 100 source types. A parallel GitHub organization email harvester fed a second stream of stolen GitHub Personal Access Tokens. These two credential pipelines supplied the initial-access credentials for the bulk of the confirmed breaches associated with frkoo. Operational security discipline by the operators was mixed. frkoo managed an EC2-based credential-harvesting pipeline, exposed their own EC2 staging IP, multiple Telegram bot tokens, a Squid proxy with hardcoded credentials and at least one public paste-site upload directly within a victim environment. They also registered a domain name impersonating the French national police, policenationale . cc though we believe this served as branding for the criminal storefront rather than as a phishing lure . The subdomain autoshop.policenationale . cc served as the web frontend for the actor’s carding autoshop: a storefront selling stolen payment-card records “fiches” enriched with BIN lookups, full cardholder PII, and an interactive geolocation map of victim addresses. The shop was delivered to customers through a Telegram Mini App @Soraki Bot backed by the actor’s “Soraki” platform, a PostgreSQL/GraphQL stack that also aggregated multiple French breach datasets including a ~400,000-record telecom/ISP dataset with IBANs and BICs into a searchable service. Across the collective of operators, during multiple target intrusions, a target’s AI API keys were stolen from the target’s enterprise software vendors. One of the stolen API keys was then used by the attacker for roughly three weeks to conduct secondary attacks, which targeted other organizations including compromising a French retail chain and probing a Web3 identity platform. They also continued post-breach attacks against a nonprofit victim, and in the case of frkoo, continued development work on their own carding shop that masqueraded as a French police department site. One of the more serious compromises was of a technology provider. The operators exfiltrated more than a terabyte of data, including hundreds of thousands of national identifiers and millions of payment card records, then staged the stolen material on a public website to pressure the victim into paying a ransom. At an airline, the threat actors accessed systems holding tens of millions of passenger records. At an energy company, the operators claimed that they could remotely control the charging current of electric-vehicle chargers installed in customers’ homes. Another affiliate appeared to specialize in supply-chain theft, where a company is compromised in order to reach the downstream data of their customers. After breaching a software-as-a-service provider, the operators used that foothold to extract data belonging to roughly 200 of the SaaS company’s downstream customer organizations. It then conducted a session-store dump containing over 2,100 Azure AD token sets spanning more than 40 corporate tenants in about 34 hours. AI agents performed nearly all of the work. In a different compromise, the actor leveraged Claude in a supply chain compromise of a software-as-a-service SaaS vendor to accelerate reconnaissance and to enable data exfiltration. The actor exploited a cross-site scripting vulnerability to gain access, escalated privileges, and ultimately exfiltrated data from thousands of downstream customer organizations. The actor used Claude by helping to identify, understand, and use developer and authentication APIs, create and convert privileged tokens, and build tools to enable bulk exports and cross-tenant data collection. Against a different target, the same attacker also claimed to have collected legitimate HackerOne bug-bounty payouts of $2,000 and $5,000 from two of the companies they infiltrated and extorted, treating BugBounty disclosure programs and intrusion as additional revenue streams against the same targets they were compromising. They also appeared to scrape HackerOne and BugBounty submissions as a form of reconnaissance during focused attacks on specific targets. This threat actor’s operational tempo was relatively consistent. One breach of an enterprise software company took only hours from first access to bulk data theft. Another compromise escalated from a single stolen developer token to full administrative control of a victim’s cloud environment in roughly three hours. This was followed by iteratively scraping internal datastores, and in the case of supply chain attacks, iteratively accessing and scraping the end customer’s data as well. We detected and banned accounts associated with the ShinyHunters associates, implemented measures to detect and disrupt future misuse from the actors, and engaged government authorities, industry partners, and victims to remediate threats posed by the actors. The use of AI during intrusions and data theft operations often resembles “ vibe hacking https://www.anthropic.com/news/detecting-countering-misuse-aug-2025 ,” wherein operators direct AI to achieve general goals like using a credential for an entity or retrieving data from a broad set of targets, then allow the AI to evaluate the environment, author and execute scripts, provide summaries, and repeatedly execute until the task is complete. Very often, the operator may not directly understand each target environment or the complexities of finding and accessing valuable information, instead deferring the specifics to the AI. Security practitioners use the phrase “living off the land” to describe attacks that use tools that are already present in the victim’s environment. The opportunistic hackers described in this section have applied the same principles to AI. The operators treated the AI supply chain itself as both a target and a resource. They stole AI API keys from multiple target environments and used them to provide additional AI compute. In every instance, the API keys involved were stolen from Anthropic customers’ environments. Anthropic’s own systems were not compromised by this actor. We examine this pattern in detail in the section on the AI supply chain. Attack lifecycle and AI integration Sourcing and recon. Most intrusions began from compromised credentials. The actor also engaged in extensive scanning, vishing, phishing and domain spoofing operations to trick employees into giving access to systems. Discover. Exposed access tokens were also discovered at industrial scale through a wide variety of automated scraping and mining projects. These included analyzing application binaries, code repositories and integrations, client side code, credential stores, container images, metadata endpoints, open storage and victim-deployed AI agents. An example of this is with one actor project that downloads all APK files from Google Play Store and searches them for exposed session tokens or other access mechanisms that could be abused for access. Validate/qualify. Everything found is tested and qualified before use or resale, such as batch cloud key validation, purpose built login oracles, live replay against production, grading for resale value, and offline cracking. Expand in-victim. One working credential is used to expand access within the victim, and used for things like whole-cluster secret dumps, admin-token amplification, CI/CD injection, database and session-table dumps, mining dumps for signing keys, and vendor-OAuth fan-out to every downstream tenant. Exfil channels. Material moves out over six channels: consumer cloud storage, a private NAS over mesh-VPN, Telegram bot streams, staging inside victim clouds, C2 channels, and plain bulk API pulls. Warehouse. Loot is warehoused for reuse and sale: a self-hosted estate that re-serves stolen databases, loot trees for each victim, a Telegram warehouse that also serves as the storefront, and working key stores. Mint/persist. New credentials and durable access are minted so the operation outlives rotation: cloud API keys in victim accounts, platform developer keys, forged sessions and 2FA codes, network backdoors. Monetize. Monetization: resale channels and key pools, direct financial theft, extortion over the stolen data, dual-hat bounty income, and bulk data held for leverage. Common workflows observed Indicators of compromise updatebeacon.duckdns . org esvfecawvjmchjslqyemho2fiduc59wzn.oast . fun soraki-proxy.20245aad98d27b1b1a2f0f103e1d7ee0.workers . dev soraki . cc soraki . work policenationale . cc emailsecure . email mozilla . ws signin-1psswoord . com on-pssword . com ari-chain . com arichain . network bitmart-mystery . com defi-claim . xyz service-infos . info 0x0 . st // Exfiltration file uploads via curl Exfiltration locations fuckyoubasil @ s3.ap-tokyo.megas4 . com https : //s3.eu-central-1.s4.mega . io/fuckyoubasil/ https : //s3.ap-tokyo.megas4 . com/