Anthropic's September report covers December 2025 through August 2026 and describes roughly 40 tracked groups across seven categories of misuse.

 

What happened

Anthropic published its fourth threat intelligence report on September 10, 2026, under the title Detecting and countering misuse of AI. It covers operations the company identified and shut down between December 2025 and August 2026. It includes seven categories of misuse: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation, which means extracting a model's capabilities without permission. The actors range from suspected state-sponsored groups to criminals working for money, commercial surveillance firms, and politically motivated individuals. Anthropic says these cases are not representative of how people use its products, and describes them as the most notable activity its threat intelligence team found.

 

Going deeper

What the AI does during an attack has changed as earlier reports from the company described operators treating the model as a research assistant or help with code. Several cases this time show something else, with the model running most of the operational chain while a person sets direction and checks the output. Anthropic tracks the actor as GTG-20006 and attributes it to a Russia state-nexus espionage operation. The group used AI-driven workflows to build infrastructure, run phishing, hold onto access in compromised systems, and steal data, hitting more than 20 organizations. Opportunistic criminals turn up in the report too, using AI to scan and exploit faster. Some race to attack newly patched flaws before organizations install the fix. Others comb through public code repositories, container stores, mobile apps, and websites hunting for credentials, tokens, and API keys.

 

What was said

Malicious use of Claude has changed since the company's earlier reports in March, August, and November 2025, Anthropic writes in the report. It says it disrupted each operation described, used the findings to tighten its safeguards, and passed intelligence to authorities and industry partners where that was appropriate. The models involved were Claude Haiku, Sonnet, and Opus.

 

In the know

Access to frontier AI models has become something criminals steal and sell on where operators obtain and rotate that access through proxy and reseller infrastructure, Anthropic reports, and split their work between models from several companies so that no single provider sees the whole operation. What actually changes hands is stolen API keys and session tokens. That explains why the same report describes attackers hunting through code repositories for credentials, since a key sitting in an application gives whoever finds it billed access to a model on someone else's account. The victim has little chance of spotting it, because the usage shows up under a paying customer's identity.

 

The big picture

Hospitals and health systems that have connected AI tools to their own systems hold API keys, and those keys sit in applications, configuration files, and automation scripts. CISA tells organizations to go through source code, infrastructure templates, automation scripts, and configuration files looking for credentials written directly into them, and to replace those with authentication that draws from a central secret store. It also advises watching authentication logs for unusual activity on privileged accounts, service accounts, and federated identities. A key connecting an AI tool to a system holding patient records is a credential reaching that data, which puts it under the same access control and audit requirements as any staff account with the same reach.

 

FAQs

What is model distillation?

Training a smaller model by repeatedly querying a larger one and learning from what it returns. Done at scale without permission, it extracts capabilities the original developer spent heavily to build, which is why the report treats it as a separate category of harm.

 

Why split an operation across several AI providers?

Each company only sees part of what the attacker is doing, so none of them has enough to identify the operation. Spreading reconnaissance, code generation, and content production across platforms also keeps any single account from showing usage patterns that would stand out.

 

How would an organization know its API key was being used by someone else?

Billing that does not match internal activity, usage volumes higher than expected, and requests arriving from unfamiliar addresses or at odd hours. Providers give customers usage dashboards and logs, though an organization that never recorded what normal looks like has nothing to compare against.

 

 

Does an exposed AI key create HIPAA exposure?

That depends on what the tool connected to it can reach. A key granting access to a service processing protected health information puts that data within reach of whoever holds the key, so it needs the same protection as any credential with comparable access.

 

What should an organization do about keys already sitting in its code?

Scan repositories and configuration files, rotate anything found, and move secrets into a managed store the application retrieves at runtime. Deleting a key from current code leaves it in version history, so rotating it matters more than removing it.