Anthropic published its September threat intelligence report on September 10. It covers malicious activity the company says it detected and disrupted between December 2025 and August 2026 across cyber operations, influence activity, surveillance, scams and fraud, biological misuse, conventional weapons development and illicit model distillation.
The methodology needs an important qualifier. Anthropic explicitly says these cases are not representative of normal Claude use. They are a selection of the most notable and novel malicious operations identified by its own threat-intelligence team.
Many of the detailed attributions therefore come from Anthropic's internal investigations. Reuters sought responses from several governments and organizations named or implicated in the reporting, but not every operation described has been independently verified in public.
Cyber AI is moving from assistant to orchestrator
That is the clearest trend in Anthropic's cyber section. The company says a majority of the operations in the report involved direct AI execution or orchestration rather than occasional chatbot assistance.
Observed workflows could span reconnaissance, tool development, exploitation and data exfiltration. Anthropic also reports multi-agent frameworks automating substantial portions of the attack chain.
Humans were still involved. Operators selected targets and reviewed exfiltrated material. What changed, according to Anthropic, was how much technical work and operational scale could be maintained with fewer people.
One case involved an operator whose tradecraft Anthropic says was consistent with public reporting on the Russia-linked Midnight Blizzard group. Its customized AI workflows allegedly covered development, infrastructure acquisition, phishing, persistence, command-and-control activity and data exfiltration.
That creates an awkward problem for defenders. Technical sophistication is becoming a weaker proxy for the resources or expertise of the human operator behind an intrusion.
Ukraine and drone technology repeatedly appear in the targeting
Anthropic says several campaigns focused on Ukrainian government, military and diplomatic organizations. One actor scanned email and remote-access services across more than two dozen Ukrainian government entities.
Drone supply-chain technology was another recurring target. The company says mailboxes belonging to at least two drone-component manufacturers were bulk-exported, while a proprietary software-development kit for a drone vision system was stolen and reverse-engineered over several days.
According to Anthropic, the resulting analysis recovered elements including product architecture, hardware bills of materials, supplier dependencies and details about an unreleased product.
Surveillance is becoming another major misuse category
Between January and July, Anthropic says it disrupted operations involving state-aligned actors, state-linked contractors and commercial surveillance vendors. The cases include activity associated with China, Iran, West Africa and the private surveillance-for-hire market.
One account was allegedly used to build a commercial platform for profiling social-media activity in Iran and the Gulf. Anthropic says it detected the project during a pilot stage and found no evidence that later stages of the surveillance chain had been deployed against real targets before the account was banned.
Another investigation identified 16 Claude accounts that Anthropic associates with two linked Iranian paramilitary and domestic-security units. The work allegedly included a malicious browser extension intended to harvest user identities from major social networks at scale.
The report also describes a system called Lakana 360, allegedly built for Mali's state intelligence service, capable of working with data associated with roughly 25 million SIM cards across the country's three mobile operators.
Some cases move well beyond conventional cybersecurity
Anthropic says one China-based actor used Claude while developing electronic-warfare and air-defense suppression software, including a simulation containing 12 targets in Taiwan.
Another actor allegedly used Claude to develop specifications and fire-control software for an anti-torpedo system intended for the Chinese navy. Anthropic says the work produced a technical proposal of more than 200 pages and included simulated adversarial reviews of the design.
Reuters reported that China's foreign ministry said it was unaware of the Anthropic report and stated that China supports the beneficial development of AI while opposing what it described as distortions and smears.
Anthropic also describes a cell in northern Yemen using Claude for software related to a guided rocket, a planned ballistic missile with a range exceeding 2,000 kilometers and another missile concept involving a hypersonic glide vehicle.
The company says it found no evidence that the group successfully fielded an operational weapon. Anthropic also acknowledges that its safeguards blocked many of the requests, but not all of them.
Five case studies involve potential biological misuse
Anthropic documents five cases in which users allegedly attempted to use its models for work that could support biological-weapons development.
The examples include research involving chikungunya, highly pathogenic avian influenza, orthopoxviruses and novel non-transmissible venoms or toxins.
In some of those cases, Anthropic says users appeared to be disguising their locations to access the service from regions where Claude was not officially available.
Thousands of AI dating profiles show a different kind of scale
Not every case involves national security. Anthropic says one China-based operation developed more than 20 dating applications populated with over 4,700 AI-generated personas.
Those profiles interacted with at least 25,000 users, according to the report. Paid human workers supplemented the automated personas to reinforce the appearance that the profiles were genuine and steer targets into scams.
The fraud itself is not novel. What AI changes is the economics of maintaining thousands of conversational identities at the same time.
Fable and Mythos barely appear in the cases
Anthropic says the operations described in the report primarily used Claude Haiku, Sonnet and Opus models. None of the reported misuse cases involved Fable or Mythos-class models except for one illicit-distillation case.
That observation has limits. It means Anthropic says it did not detect these particular misuse patterns on those newer model classes during the reporting period. It does not demonstrate that they are inherently immune to similar abuse.
Post-detection response is still a major part of the security model
Anthropic says it banned the accounts involved, built new behavioral detections from what it observed and shared indicators with authorities and industry partners when appropriate.
The harder problem is increasingly compositional. A safety system has to identify not only one obviously malicious prompt, but a sequence of individually plausible actions spread across tools, agents and sessions that together form an offensive operation.
That may be the biggest change in the report. Risk is no longer defined only by what a model can answer. It increasingly depends on what an automated system can make that model do, step after step, for hours at a time.