Anthropic has released a comprehensive report detailing its efforts to detect and disrupt misuse of its Claude AI models over an eight-month period ending in August 2026. The company’s Threat Intelligence team uncovered a range of malicious activities spanning cyber operations, influence campaigns, surveillance, scams, biological misuse, conventional weapons development, and illicit distillation. These activities involved various Claude models including Haiku, Sonnet, and Opus, but notably excluded the more safeguarded Fable and Mythos-class models except in one distillation case.
The report reveals that AI has significantly lowered the barrier to entry for complex cyberattacks, enabling individual actors and smaller groups to conduct operations previously requiring extensive expertise and resources. Threat actors, ranging from state-sponsored groups to financially motivated criminals and hacktivists, have employed AI to automate reconnaissance, exploitation, data exfiltration, and tool modification, often running multi-agent frameworks with minimal human oversight.
One highlighted case involved a Russian espionage group, linked to the Midnight Blizzard campaign, which used AI to automate malware development, phishing, and evasion of security detections. This group targeted Ukrainian government entities, military drone suppliers, and diplomatic organizations, employing AI to monitor and adapt their tools in real time. Another case detailed opportunistic cybercriminals affiliated with the ShinyHunters collective, who leveraged AI to accelerate credential harvesting and supply-chain attacks, affecting hundreds of organizations.
Anthropic also identified autonomous exploit foundries operated by Chinese-speaking actors, who used Claude to conduct continuous vulnerability research and develop zero-day exploits against security appliances. These operations included persistent intelligence collection and malware development, demonstrating AI’s role in sustaining complex cyber campaigns.
The report further covers influence operations where AI was used to generate fake social media profiles, news articles, and coordinated messaging to manipulate public opinion across multiple countries. Examples include Russian state-aligned campaigns in Africa, commercial influence-as-a-service networks operating globally, and politically motivated actors targeting elections in Malaysia and Kenya.
Surveillance misuse was another significant area, with state-aligned actors from China, Iran, and West Africa employing Claude to build mass-interception platforms, analyze social media data, and profile dissidents. Notably, Anthropic uncovered operations involving malicious browser extensions and AI-assisted recruitment targeting Uyghur populations in Syria.
In the realm of conventional weapons, Anthropic disrupted actors using Claude to develop software for guided rockets, drone swarms, electronic warfare, and procurement of dual-use goods. These cases spanned Yemen, China, and Russia, illustrating AI’s expanding role in weapons engineering and military logistics.
Biological misuse remains a critical concern. Anthropic identified several cases where researchers, including those linked to state programs, used Claude to assist in gain-of-function viral research, toxin optimization, and orthopoxvirus studies. These activities often involved evasion of regional restrictions and safeguards, underscoring the dual-use nature of biological research facilitated by AI.
The report also addresses illicit distillation campaigns, where unauthorized entities—primarily based in China—used stolen API keys, fraudulent accounts, and proxy networks to extract Claude’s reasoning capabilities for training competing AI models. Major technology companies such as Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi were implicated in large-scale distillation efforts, prompting Anthropic to implement layered defenses including account verification, behavioral detection, and technical safeguards like reasoning trace summarization.
Anthropic emphasizes that AI’s diffusion across the threat landscape has leveled the playing field, granting diverse actors access to advanced capabilities that were once limited to well-resourced state entities. The company continues to evolve its safeguards, collaborate with industry and government partners, and share intelligence to mitigate emerging threats. The report aims to inform the broader AI community, policymakers, and security professionals about the evolving risks and necessary defenses associated with frontier AI technologies.