Anthropic's September 2026 Threat Report: Hackers, Spies and Propagandists Tried to Weaponise Claude, and Were Caught
A Russian espionage group, a lone hacker in France, a company selling election manipulation as a service. Anthropic's latest threat report lists who tried to misuse Claude over nine months, what they got, and where each one was stopped. A plain-language walk through it.
A Russian state-linked spy group used AI to rewrite its own malware every time antivirus software caught it. One French-speaking hacker, working alone, built a search engine for finding and exposing people connected to a political movement. A company in Turkey sold what it described as a military-grade system for steering a national election. All three were using Claude. All three were caught and cut off. That is the short version of a long report Anthropic published on 10 September 2026, and it is worth reading even if you have never used an AI tool, because the people in it are the same people who send the phishing email to your finance team.
This piece summarises, in plain language, Detecting and countering misuse of AI: September 2026, published by Anthropic on 10 September 2026, and covering activity its Threat Intelligence team disrupted between December 2025 and August 2026. It is Anthropic's fourth such report, after March, August and November 2025. Every figure below is taken from the report itself; where the report gives a range or a rough number, so do I. Two things to keep in mind: the report describes only what one company caught on its own platform, and it is written by the company whose product was misused. Neither makes it wrong. Both are reasons to read it as evidence rather than as the whole picture.
AI has not made attackers cleverer. It has made a small crew, or one person with stolen credentials, able to run an operation that used to need a well-funded team.
What the report covers
Nine months, seven kinds of harm. Anthropic groups everything it disrupted under these headings:
Breaking into networks, stealing data, writing and hiding malware.
Fake news sites, fake social accounts, propaganda dressed up as journalism.
Tracking, profiling and exposing individuals.
Including a network of fake dating apps built to take people's money.
Research requests whose stated purpose was legitimate but whose method carried weapons-grade risk.
Drone technology and its supply chain.
Using the model's answers to train a copy of it without permission.
The spies: an attack that heals itself
The group Anthropic tracks as GTG-20006 looks, by its methods, like the Russian state-linked crew publicly known as Midnight Blizzard. Its target list ran to more than twenty organisations across government, defence and diplomacy, concentrated on Ukraine and Europe but reaching into the Middle East and Asia.
The target list is not the interesting part. The method is. When a security product detected the group's malware, its AI-driven workflow would rewrite the code and send it back out, again and again, until it slipped past. What used to be a slow, manual game of cat and mouse became a loop that runs on its own.
- Malware lands on a target machine.
- Antivirus catches it and publishes a signature.
- The AI rewrites the code so the signature no longer matches.
- It goes back out, and the cycle repeats, faster than a human team could keep up.
The same group tampered with the DNS of at least three companies that run hotel guest WiFi, so that guests connected to Ukraine, including officials and drone manufacturers, could be steered towards malware. If you have ever accepted the hotel's WiFi terms without reading them, you were the intended audience.
The thieves: one person, 1.8 million apps
A cluster of financially motivated operators linked to the ShinyHunters extortion crowd shows what scale now looks like. One operator downloaded and pulled apart 1.8 million distinct Android apps looking for passwords and keys that developers had left inside the code. Those keys fed a pipeline that reached into an airline holding tens of millions of passenger records, a technology provider from which more than a terabyte of data was taken, and dozens of customers of a compromised software vendor.
Elsewhere, a Chinese-speaking group, two of whose operators were undergraduates at a university in Hunan, ran several AI-driven workstreams at once: live break-ins, reconnaissance on foreign governments, and a hunt for undiscovered flaws in major security products that turned up more than a dozen candidate zero-days in a single month. Roughly fifty organisations were on its list. The collection kept running while the students were offline.
The loner: a doxxing engine built solo
The case that best makes the report's point involves no state and no gang. A French-speaking hacktivist used AI-assisted coding to find a previously undocumented flaw in WordPress, then built a search platform, alone, that cross-referenced tens of millions of breached records, including national health identifiers, so that anyone could look up people affiliated with a particular political movement by name. Of 42 targets tracked, 14 were compromised, yielding between 12 and 26 gigabytes of database dumps.
Anthropic's conclusion is blunt: how sophisticated an attack looks no longer tells you who is behind it.
The keys themselves are now the loot
The finding most useful to any business that has started paying for AI tools is this one. Attackers are not only using AI. They are stealing access to it, and treating a stolen API key as three things at once.
Working keys are traded like any other stolen credential.
The attacker's own operations run on your bill.
Whatever they do gets attributed to the legitimate key holder. You.
One Russian-speaking group hit around thirty AI companies in four days. In one attempt it planted instructions inside an AI vendor's own automated testing environment so that the environment handed over the production keys it held. The stated goal was access to a pre-release Claude model. It did not get there. Separately, "discount Claude access" resellers were found to be neither discounted nor Claude: customer traffic was quietly routed to a different, cheaper model while the reseller kept the credentials people signed up with.
Treat every AI API key and session token exactly as you treat the password to your accounting system or your bank portal. Attackers already do.
The propagandists: AI as the newsroom
Nine influence operations were shut down, originating in Russia, Iran, Turkey and across the Gulf, South Asia, Africa and Europe, several timed to national elections.
Two details from these cases deserve a pause. First, in the Malaysian case the model refused or partly refused at several points, including once it recognised a fabricated dossier as material for defaming a politician, so the operator had to keep softening the request to get anything at all. Second, because Claude sits upstream of the platforms where content is posted, most of these operations were caught before they found a real audience. The fabricated articles and fake accounts drew little genuine engagement. Where propaganda did reach people, it travelled through outlets that already had an audience, such as state broadcasters, not through the fake networks.
Biology, weapons and the hard cases
The report is more guarded here, for obvious reasons. It describes five biological case studies, all of them requests whose stated purpose was scientific research but whose methods carried weapons-relevant risk, and it says openly that newer models can no longer be assumed to sit safely below the threshold at which they could give meaningful help with a biological weapon. On the conventional side, a complete proprietary software kit for a drone vision system was stolen in one intrusion, and drone supply chains recur as targets across the cyber cases. Anthropic also notes that it cannot always tell a legitimate research request from a harmful one, which is an honest admission about how much harder this category is than cybercrime or propaganda.
The sentence that changes the job of every security team
For decades, the defender's cheapest move was to publish a new detection signature and force the attacker back to the drawing board. The report says that lever is weakening. Its own words are that AI has "inverted the cost back onto defenders": an attacker with capable enough tools can notice it has been detected and rebuild, often faster than the defence can respond.
Six things to take away
- The skill gap has closed. A lone hacktivist, a small criminal crew and a state espionage group all ran multi-victim campaigns with strikingly similar AI-driven methods.
- Speed, not just volume. Full breaches, from first stolen credential to complete control, in two to three hours.
- Your AI keys are a target. Guard them like production database credentials.
- Catching it early works. Sitting upstream of publication let many influence operations be stopped before anyone read them.
- The model pushed back. Across several cases Claude refused the worst requests, forcing operators to negotiate around it rather than simply get what they asked for.
- This is a running fight. Anthropic expects continued escalation and says the report reflects only what it caught, not everything that was tried.
What this means for a finance team in India
This section is my own reading, not part of the report.
Nothing in the report is about India specifically, and that is precisely why it matters here. The hotel WiFi trick, the stolen developer token, the fake reseller offering cheap AI access: none of these care where the victim sits. Three practical checks, none of which need a security budget. First, find out whether anyone in your company has pasted an API key into a shared document, a chat, or a spreadsheet; if so, rotate it today. Second, treat any "discounted" AI subscription bought outside the vendor's own site as a credential leak waiting to happen. Third, if a vendor email arrives asking you to click through to "re-verify" something, the fact that it is beautifully written is no longer evidence that a human wrote it.
The full report, including the technical indicators security teams will want, is at anthropic.com.
Frequently Asked Questions
Were any of these attacks successful? Some intrusions did real damage before they were disrupted: the airline records, the terabyte taken from a technology provider, the drone software kit. What the report claims is that every operation it describes was identified and shut down on its platform, and that most influence operations were stopped before reaching an audience.
Does this mean AI tools are unsafe for my business to use? No. The report describes people misusing a tool, not the tool attacking its users. The practical risk to an ordinary business is the same as with any cloud service: leaked credentials and convincing phishing. Both are manageable with basic hygiene.
Which models were being misused? The report says the disrupted cases involved Claude's Haiku, Sonnet and Opus models, with the newer Fable and Mythos-class models almost absent, which Anthropic attributes to the additional safeguards on those tiers.
Is a "stolen API key" really that serious? Yes. In one case a single stolen developer token was turned into full administrative control of a company's cloud environment in about three hours. A key is a password that machines use, and it is usually far less protected than a human's.
Who wrote this summary and why? A chartered accountant working in industry, not a security professional. The interest is practical: finance teams hold the money, sign off the vendors and receive the phishing emails, so they should understand what the people on the other side are now able to do.