WRITTEN IN PLAIN AMERICAN ENGLISH.
About
CLAY TRIBUNE.
Advertisement

Anthropic Report: Threat Actors Abused Claude AI in Cyber Attacks, Influence Campaigns, and More

Anthropic's report documents how threat actors used its Claude AI in cyber, influence, and surveillance operations, and what Anthropic did about it.

By mitch·3 min read
A glowing digital brain of AI code represents misuse of generative systems in cyber operations.

Over the past eight months, Anthropic has published a report on how malicious users employed its Claude AI system for cyber operations, influence campaigns, and surveillance. The company claims it stopped the activity, tightened its protections, and worked with government officials and other businesses to share information.

The document examines activities spotted from December 2025 through August 2026, spanning seven fields: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. The work relied on Claude Haiku, Sonnet, and Opus models. No misuse cases tied to Claude Fable or Mythos-class models were found.

Anthropic refers to the people causing danger as “Generative Threat Groups,” or GTGs. It judges the extent of their harm using a single measure: how much more damage AI enables beyond what human-only operations could manage on their own. That measure is called “uplift”, which combines speed, scale, and depth into one figure.

Advertisement

Cyber Operations: From Assistant to Orchestrator

According to the report, AI has closed the gap between well-funded state-backed operations and lone operators. A hacktivist, a financially driven individual, and a state espionage agent each carried out multi-victim campaigns that previously would have required several skilled operators and specialized knowledge.

“Every layer of offensive operations has been uplifted by AI, from reconnaissance and tool development to data processing and exploitation,” the report states.

Public Scaffolding Spreads Across Actors

Anthropic documented an operating model used by a suspected state-sponsored campaign to carry out autonomous attacks in November 2025. Since then, that model has spread across every class of actor investigated.

The public frameworks for offensive agents, such as PentAGI, hand down the same building plans to anyone who downloads them. Those running operations with these tools come from a wide set of places, including state services and lone individuals, across an expanding number of countries.

Case Studies and What They Show

The documentation cites particular case studies, such as GTG-50014 and GTG-20006, to illustrate increased capabilities and the adoption of AI-enabled kill chains. In both instances, the company intervened to stop the activity, reinforced its AI safeguards, and communicated intelligence to authorities and industry partners when fitting.

Models Used Across Cases

Across all cyber operations cases, the Haiku, Sonnet, and Opus models were employed. The Claude Fable and Mythos-class models were left out of the misuse cases, with one exception: an illicit distillation case that involved a different model instead.

Model Class Role in Misuse
Haiku, Sonnet, Opus Used in cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation
Claude Fable, Mythos Not involved in misuse, except one illicit distillation case

The Broader Picture

According to Anthropic, the research will enable other platform builders to spot similar trends on their own systems, offer governments and civic organizations a clearer picture of how new dangers emerge, and build stronger shared protections.

Anthropic warns that as models grow more capable, their risks will rise unless AI builders and society’s defenders step in to make them safer. The company hopes the report aids others in spotting the same trends.

Key Details

  • Report period: December 2025 to August 2026
  • Harm areas: Seven, including cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation
  • Models used: Claude Haiku, Sonnet, Opus
  • Models not involved in misuse: Claude Fable or Mythos-class
  • Threat actors: Suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, politically motivated individuals

The Company’s View

The company regards the report as an obligation to reveal any harmful abuse of its offerings. It considers it a duty to make public whatever it discovers about how artificial intelligence gets put to wrongful use.

Anthropic warns that the hazards of artificial intelligence will rise as these systems grow more powerful, unless developers and society’s guardians take action to protect against them.

This threat report comes from a collection of reports produced by Anthropic, which includes earlier volumes published in March, August, and November 2025.

Source: anthropic.com

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.