Back to FeedTechnology

Anthropic releases September 2026 report on attempted Claude misuse

Anthropic’s September 2026 threat report describes attempted misuse of Claude across cyber operations, surveillance and fraud, along with the company’s defensive actions.

3 min read|Mefico News News Desk|
Aa
People-free and logo-free cybersecurity operations center representing Anthropic’s September 2026 AI threat report
Representative image generated with artificial intelligence.

Anthropic released its September 2026 threat intelligence report on September 10, examining attempts to misuse Claude models. The company grouped activity detected and disrupted between December 2025 and August 2026 into seven areas, including cyber operations, surveillance, influence activity, scams, illicit model distillation and other high-risk research. Anthropic stressed that the case studies were not representative of ordinary use. They were selected as some of the most notable and novel forms of harmful activity identified by its investigators.

A central finding is that artificial intelligence is moving beyond a question-and-answer role in some threat operations. Anthropic said several actors used multi-agent workflows to coordinate sequences of tasks, while people continued to choose targets and review results. The company argues that this can increase the speed, scale and range of activities available to a smaller group. Reuters reports published on September 10 and 11 independently confirmed the report’s release and its broad findings.

According to Anthropic, the investigated activity involved a wide range of actors, from suspected state-linked groups to financially motivated networks and commercial surveillance providers. The company said Claude was used or tested in cyber operations, influence campaigns, monitoring projects and fraud involving synthetic profiles. Many of the attributions rely on Anthropic’s own account data and threat analysis. Not every person, institution or government named or implied by the report has been independently verified as responsible.

Associated Press highlighted Anthropic’s claim that users in northern Yemen attempted to use Claude in software work connected to advanced weapons systems. Anthropic said it blocked the accounts and found no evidence that an operational system was successfully fielded. That distinction is important: the report describes attempted misuse but does not say every effort achieved its technical goal. This article does not reproduce dangerous methods or actionable technical instructions from any of the cases.

On cybersecurity, Anthropic said some actors used AI across consecutive tasks such as research, code generation, infrastructure management and processing collected information. The company’s assessment is that a sophisticated-looking campaign may no longer reliably indicate a large team with deep specialist expertise. For defenders, that makes it harder to judge an actor’s resources only from the complexity or speed of the observed operation.

The report also separates scams and surveillance into dedicated sections. Anthropic said it identified networks designed to mislead users through synthetic identities and systems built to classify social-media activity. Reuters and Folha de S.Paulo reported that the company closed linked accounts and shared selected findings with authorities or industry partners. Their coverage also notes that some parties did not respond, while others rejected or disputed allegations associated with the broader report.

Anthropic says its defensive response goes beyond closing individual accounts. It incorporated indicators from the cases into model safeguards, enforcement systems and threat intelligence processes, and shared information with public and private partners when appropriate. The company also said none of the listed misuse cases involved Claude Fable or Mythos-class models, apart from one illicit distillation case. This detail narrows the scope of the findings and avoids implying that every current Claude model was involved.

The publication highlights two needs for AI security: providers must continuously examine real-world use, and the industry needs channels for sharing verifiable threat indicators. The findings should not automatically be treated as a complete picture of global AI use because they come from one company’s observations. Across Anthropic, Reuters, AP and Folha, the confirmed development is that Anthropic published a new report, said it disrupted multiple harmful operations and described updates to its safeguards. Broader attribution claims remain subject to independent scrutiny.

Sources

This article was prepared with AI assistance and its sources were checked by the Mefico News News Desk.

Like/dislike buttons become active once you finish reading the article.