Overview
- Anthropic published a 154-page threat report on Sept. 11 that documents December 2025–August 2026 cases where state‑aligned groups and criminal networks used its Claude models for surveillance, influence, cyberattacks, weapons work, and sensitive biological research.
- The company says it banned implicated accounts, added new detections, took down some relay channels, and shared intelligence with authorities but admits safeguards did not stop all misuse.
- Anthropic named Iranian institutions it says ran state‑aligned influence and persona operations that profiled hundreds of Israelis and members of the Jewish diaspora and said Russia‑linked freelancers used Claude to help develop an autonomous combat‑drone swarm with target‑selection capabilities.
- The report describes criminal automation at scale, including a pipeline that mass‑downloaded 1.8 million Android apps and a suspected ShinyHunters actor that extracted thousands of authentication tokens in hours with AI agents doing most of the work.
- Anthropic warns actors evaded per‑prompt filters by fragmenting tasks, routing traffic through VPNs and resellers, and performing large‑scale model distillation, and calls for coordinated monitoring, incident reporting, and tighter access controls as model capabilities rise.