CA. Akhilesh Kumarcaakhilesh.in
FINTECHAnthropic's September2026 Threat Report:Hackers, Spies andPropagandists Tried…The skill gap between a lone hacker and astate spy agency has narrowed to the price ofa stolen API key.CA Akhilesh Kumar· caakhilesh.inPROBES AGAINST THE MODEL, BLOCKEDCYBERINFLUENCESCAMSSURVEILLANCEWEAPONSSEPT 2026 REPORT7Kinds ofmisuse tracked9Influenceoperationsshut down~3 hrsFrom onestolen tokento…PROBES AGAINST THE MODEL, BLOCKEDCYBERINFLUENCESCAMSSURVEILLANCEWEAPONSSEPT 2026 REPORTNº 52
Fintech · 9 min read

Anthropic's September 2026 Threat Report: Hackers, Spies and Propagandists Tried to Weaponise Claude, and Were Caught

A Russian espionage group, a lone hacker in France, a company selling election manipulation as a service. Anthropic's latest threat report lists who tried to misuse Claude over nine months, what they got, and where each one was stopped. A plain-language walk through it.

By CA Akhilesh Kumar ACA, Institute of Chartered Accountants of India (2022) · Gurgaon
FintechArtificial IntelligenceCybersecurityAnthropic

A Russian state-linked spy group used AI to rewrite its own malware every time antivirus software caught it. One French-speaking hacker, working alone, built a search engine for finding and exposing people connected to a political movement. A company in Turkey sold what it described as a military-grade system for steering a national election. All three were using Claude. All three were caught and cut off. That is the short version of a long report Anthropic published on 10 September 2026, and it is worth reading even if you have never used an AI tool, because the people in it are the same people who send the phishing email to your finance team.

This piece summarises, in plain language, Detecting and countering misuse of AI: September 2026, published by Anthropic on 10 September 2026, and covering activity its Threat Intelligence team disrupted between December 2025 and August 2026. It is Anthropic's fourth such report, after March, August and November 2025. Every figure below is taken from the report itself; where the report gives a range or a rough number, so do I. Two things to keep in mind: the report describes only what one company caught on its own platform, and it is written by the company whose product was misused. Neither makes it wrong. Both are reasons to read it as evidence rather than as the whole picture.

The one line to remember

AI has not made attackers cleverer. It has made a small crew, or one person with stolen credentials, able to run an operation that used to need a well-funded team.

What the report covers

Nine months, seven kinds of harm. Anthropic groups everything it disrupted under these headings:

1Cyber operations

Breaking into networks, stealing data, writing and hiding malware.

2Influence operations

Fake news sites, fake social accounts, propaganda dressed up as journalism.

3Surveillance

Tracking, profiling and exposing individuals.

4Scams and fraud

Including a network of fake dating apps built to take people's money.

5Biological misuse

Research requests whose stated purpose was legitimate but whose method carried weapons-grade risk.

6Conventional weapons

Drone technology and its supply chain.

7Illicit distillation

Using the model's answers to train a copy of it without permission.

Dec 2025 to Aug 2026The nine months the report covers
Haiku, Sonnet, OpusThe models the abusers were using
Almost noneMisuse found on the newer Fable and Mythos-class models, which carry extra safeguards
All of itEvery operation described was disrupted and the accounts shut down

The spies: an attack that heals itself

The group Anthropic tracks as GTG-20006 looks, by its methods, like the Russian state-linked crew publicly known as Midnight Blizzard. Its target list ran to more than twenty organisations across government, defence and diplomacy, concentrated on Ukraine and Europe but reaching into the Middle East and Asia.

The target list is not the interesting part. The method is. When a security product detected the group's malware, its AI-driven workflow would rewrite the code and send it back out, again and again, until it slipped past. What used to be a slow, manual game of cat and mouse became a loop that runs on its own.

  1. Malware lands on a target machine.
  2. Antivirus catches it and publishes a signature.
  3. The AI rewrites the code so the signature no longer matches.
  4. It goes back out, and the cycle repeats, faster than a human team could keep up.

The same group tampered with the DNS of at least three companies that run hotel guest WiFi, so that guests connected to Ukraine, including officials and drone manufacturers, could be steered towards malware. If you have ever accepted the hotel's WiFi terms without reading them, you were the intended audience.

The thieves: one person, 1.8 million apps

A cluster of financially motivated operators linked to the ShinyHunters extortion crowd shows what scale now looks like. One operator downloaded and pulled apart 1.8 million distinct Android apps looking for passwords and keys that developers had left inside the code. Those keys fed a pipeline that reached into an airline holding tens of millions of passenger records, a technology provider from which more than a terabyte of data was taken, and dozens of customers of a compromised software vendor.

How long a break-in now takes

Old way
days to weeks
Now
about three hours

In one case a single stolen developer token became full administrative control of a company's cloud environment in roughly three hours. The "old way" bar is illustrative; the three-hour figure is the report's.

Elsewhere, a Chinese-speaking group, two of whose operators were undergraduates at a university in Hunan, ran several AI-driven workstreams at once: live break-ins, reconnaissance on foreign governments, and a hunt for undiscovered flaws in major security products that turned up more than a dozen candidate zero-days in a single month. Roughly fifty organisations were on its list. The collection kept running while the students were offline.

The loner: a doxxing engine built solo

The case that best makes the report's point involves no state and no gang. A French-speaking hacktivist used AI-assisted coding to find a previously undocumented flaw in WordPress, then built a search platform, alone, that cross-referenced tens of millions of breached records, including national health identifiers, so that anyone could look up people affiliated with a particular political movement by name. Of 42 targets tracked, 14 were compromised, yielding between 12 and 26 gigabytes of database dumps.

Anthropic's conclusion is blunt: how sophisticated an attack looks no longer tells you who is behind it.

The keys themselves are now the loot

The finding most useful to any business that has started paying for AI tools is this one. Attackers are not only using AI. They are stealing access to it, and treating a stolen API key as three things at once.

Use oneSomething to sell

Working keys are traded like any other stolen credential.

Use twoFree compute

The attacker's own operations run on your bill.

Use threeCover

Whatever they do gets attributed to the legitimate key holder. You.

One Russian-speaking group hit around thirty AI companies in four days. In one attempt it planted instructions inside an AI vendor's own automated testing environment so that the environment handed over the production keys it held. The stated goal was access to a pre-release Claude model. It did not get there. Separately, "discount Claude access" resellers were found to be neither discounted nor Claude: customer traffic was quietly routed to a different, cheaper model while the reseller kept the credentials people signed up with.

If you run a business

Treat every AI API key and session token exactly as you treat the password to your accounting system or your bank portal. Attackers already do.

The propagandists: AI as the newsroom

Nine influence operations were shut down, originating in Russia, Iran, Turkey and across the Gulf, South Asia, Africa and Europe, several timed to national elections.

8,913Fabricated articles published by one France-based advertising agency, across about 70 fake news sites in around 20 languages, taking whichever political side was paying that month
222Malaysian parliamentary constituencies profiled, one by one, by a Turkish company selling a "military-grade" political operations platform that ran about a thousand fake accounts
2017Year the Wagner Group set up Radio Lengo Songo in the Central African Republic, later used to pipe AI-drafted pro-Russia, anti-France content into ordinary programming
RT, Sputnik Moldova, RIA NovostiRussian state-aligned outlets through which Claude-generated content was ultimately published and broadcast

Two details from these cases deserve a pause. First, in the Malaysian case the model refused or partly refused at several points, including once it recognised a fabricated dossier as material for defaming a politician, so the operator had to keep softening the request to get anything at all. Second, because Claude sits upstream of the platforms where content is posted, most of these operations were caught before they found a real audience. The fabricated articles and fake accounts drew little genuine engagement. Where propaganda did reach people, it travelled through outlets that already had an audience, such as state broadcasters, not through the fake networks.

Biology, weapons and the hard cases

The report is more guarded here, for obvious reasons. It describes five biological case studies, all of them requests whose stated purpose was scientific research but whose methods carried weapons-relevant risk, and it says openly that newer models can no longer be assumed to sit safely below the threshold at which they could give meaningful help with a biological weapon. On the conventional side, a complete proprietary software kit for a drone vision system was stolen in one intrusion, and drone supply chains recur as targets across the cyber cases. Anthropic also notes that it cannot always tell a legitimate research request from a harmful one, which is an honest admission about how much harder this category is than cybercrime or propaganda.

The sentence that changes the job of every security team

For decades, the defender's cheapest move was to publish a new detection signature and force the attacker back to the drawing board. The report says that lever is weakening. Its own words are that AI has "inverted the cost back onto defenders": an attacker with capable enough tools can notice it has been detected and rebuild, often faster than the defence can respond.

Six things to take away

  1. The skill gap has closed. A lone hacktivist, a small criminal crew and a state espionage group all ran multi-victim campaigns with strikingly similar AI-driven methods.
  2. Speed, not just volume. Full breaches, from first stolen credential to complete control, in two to three hours.
  3. Your AI keys are a target. Guard them like production database credentials.
  4. Catching it early works. Sitting upstream of publication let many influence operations be stopped before anyone read them.
  5. The model pushed back. Across several cases Claude refused the worst requests, forcing operators to negotiate around it rather than simply get what they asked for.
  6. This is a running fight. Anthropic expects continued escalation and says the report reflects only what it caught, not everything that was tried.

What this means for a finance team in India

This section is my own reading, not part of the report.

Nothing in the report is about India specifically, and that is precisely why it matters here. The hotel WiFi trick, the stolen developer token, the fake reseller offering cheap AI access: none of these care where the victim sits. Three practical checks, none of which need a security budget. First, find out whether anyone in your company has pasted an API key into a shared document, a chat, or a spreadsheet; if so, rotate it today. Second, treat any "discounted" AI subscription bought outside the vendor's own site as a credential leak waiting to happen. Third, if a vendor email arrives asking you to click through to "re-verify" something, the fact that it is beautifully written is no longer evidence that a human wrote it.

The full report, including the technical indicators security teams will want, is at anthropic.com.

Frequently Asked Questions

Were any of these attacks successful? Some intrusions did real damage before they were disrupted: the airline records, the terabyte taken from a technology provider, the drone software kit. What the report claims is that every operation it describes was identified and shut down on its platform, and that most influence operations were stopped before reaching an audience.

Does this mean AI tools are unsafe for my business to use? No. The report describes people misusing a tool, not the tool attacking its users. The practical risk to an ordinary business is the same as with any cloud service: leaked credentials and convincing phishing. Both are manageable with basic hygiene.

Which models were being misused? The report says the disrupted cases involved Claude's Haiku, Sonnet and Opus models, with the newer Fable and Mythos-class models almost absent, which Anthropic attributes to the additional safeguards on those tiers.

Is a "stolen API key" really that serious? Yes. In one case a single stolen developer token was turned into full administrative control of a company's cloud environment in about three hours. A key is a password that machines use, and it is usually far less protected than a human's.

Who wrote this summary and why? A chartered accountant working in industry, not a security professional. The interest is practical: finance teams hold the money, sign off the vendors and receive the phishing emails, so they should understand what the people on the other side are now able to do.