Anthropic threat report: Claude used for cyber ops, weapons, and espionage
Anthropic published (covered Sept 10–11) its September 2026 threat-intelligence report—“Countering misuse of AI”—detailing operations it disrupted from December 2025 through August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams/fraud, biological misuse, conventional weapons development, and illicit distillation. Cases span suspected state-linked and criminal actors using Claude Haiku/Sonnet/Opus (not Fable/Mythos, aside from one distillation case), including a Russian-nexus espionage cluster Anthropic links to Midnight Blizzard–style tradecraft that automated phishing, implant rebuild/redeploy when detections fired, hotel Wi‑Fi DNS hijacking, and drone-supply-chain targeting; Chinese student-run offensive campaigns; Iranian influence ops; Yemen-linked missile/rocket software assistance; electronic-warfare/radar-jamming tooling; and commercial spyware–style surveillance. Anthropic says it blocked the activity, tightened safeguards (including dual-use bio restrictions on newer models), and shared intelligence with authorities and industry partners. Distinct from the Sept 9 alignment-assessment / fourth Opus 4.6 cyber incident card, from Coxon’s resignation over RSI racing, and from OpenAI’s rogue-agent website disclosures.






