Anthropic published a threat report on September 10, 2026, showing that AI has closed the skill gap that once separated state-sponsored hackers from lone criminals, and detailing misuse of its Claude models across seven categories of harm.
What happened
Anthropic's report covers activity it observed between December 2025 and August 2026 across cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. The company disrupted each operation, strengthened its safeguards, and shared intelligence with authorities and industry partners where appropriate.
The cyber cases include a Russian-aligned espionage campaign that hit more than 20 government and defense organizations across Ukraine and Europe, two Chinese undergraduates who ran an automated exploit foundry, ShinyHunters-affiliated actors who dumped thousands of cloud access tokens, and a lone hacktivist who targeted European political parties using stolen API keys.
Going deeper
One case involved an actor using the handle "JackPoterz," whose behavior aligned with Russian state espionage and matched patterns linked to Midnight Blizzard. The actor used a custom toolkit made up of tWindows-based implants, a mobile exploitation kit, a credential-stealing tool targeting browser password stores, a phishing platform built to mimic government targets, and an administrative console for managing compromised accounts. The AI reportedly monitored whether security products detected the actor's malware and autonomously modified and rebuilt it to evade detection when flagged.
The same actor exported mailboxes at drone component manufacturers, stole a software development kit for a drone vision system, compromised hotel Wi-Fi vendors to reach guests through DNS hijacking, took over WhatsApp accounts using headless browsers, and stole more than 300,000 national identity records from a North African government agency.
Separately, Chinese-speaking operators, including undergraduates at a Chinese university, used Claude for continuous vulnerability research, producing more than a dozen possible zero-day findings in a single month by running "agent swarms" that divided work among parallel subagents and retained memory across sessions.
ShinyHunters-linked clusters used AI agents to carry out nearly all the work in a supply-chain breach that dumped more than 2,100 Azure access tokens across over 40 corporate tenants in about 34 hours. A separate compromise went from one stolen developer token to full control of a victim's cloud environment in roughly three hours.
The report also describes distillation attacks Anthropic says seven China-based labs, including Alibaba, DeepSeek, Moonshot AI, Xiaomi, and Zhipu, have carried out since February to train their own models on Claude's outputs. Anthropic said Alibaba-affiliated operators ran its largest measured attack, using thousands of fraudulent accounts to harvest outputs from Claude Opus models. Moonshot and DeepSeek reportedly forwarded their own customers' requests to Claude and returned the answers as their own, without those customers' knowledge, exposing data that included surveillance footage pulled by a user likely affiliated with the People's Liberation Army.
Earlier the same week, the NSA, CISA, and the FBI issued a joint advisory accusing Chinese AI companies of a systematic effort to illegally distill U.S. frontier AI models.
Read also: Who are the ShinyHunters?
What was said
Anthropic said that most of the operations it described were enabled by AI, "Via direct execution or orchestration." On the cloud token dump, the company said AI agents performed nearly all of the work involved. Anthropic also said the distillation practices by Moonshot and DeepSeek are likely inconsistent with privacy laws and the labs' own terms of service.
Why it matters
This report documents, with named cases and figures rather than general warnings, that AI has eliminated sophistication as a signal of who is behind a cyberattack. Anthropic's cases show a hacktivist working alone, a pair of undergraduates, and scattered criminal affiliates all running operations that a year earlier would have needed teams of skilled specialists. That change has direct consequences for defenders and policymakers, since threat attribution and resourcing decisions built on the old assumption may no longer be useful. The findings also show that AI misuse isn't limited to hacking, but extends to companies allegedly using Claude to train competing models while exposing their own customers' data without consent.
The bottom line
Anthropic frames its disclosures as an early look at a fast-shifting threat environment, and argues that "security through obscurity" no longer works when AI can help any actor, regardless of skill level, scale up an attack. Organizations and defenders will need to plan around that assumption rather than around who they think is skilled enough to attack them.
FAQs
What is a distillation attack in AI?
Distillation is a technique where one company trains its own AI model by learning from the outputs of a more advanced model, copying its capabilities without building them from scratch.
What is Midnight Blizzard?
Midnight Blizzard is the name security researchers use for a Russian state-linked hacking group historically tied to Russia's foreign intelligence service.
What is an "agent swarm" in AI terms?
An agent swarm is a setup where multiple AI agents work in parallel on different parts of a task, coordinated by a lead agent that divides the work among them.
How does a hacktivist differ from a state-sponsored hacker?
A hacktivist acts independently for political or ideological reasons, while a state-sponsored hacker works on behalf of, or with support from, a national government.
