Enterprise & Security

Anthropic's threat report: Claude is orchestrating attacks now, not just assisting them

3 min read AI-generated

Eight months, seven categories of misuse, dozens of cases. Anthropic's new threat intelligence report is mostly a stocktake of what happens when attackers hand their work to agents.

Featured image for "Anthropic's threat report: Claude is orchestrating attacks now, not just assisting them"

Anthropic published its September 2026 threat intelligence report today. It covers December 2025 through August 2026 and sorts the cases into seven categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons, and distillation.

Haiku, Sonnet and Opus were the models involved. Fable and Mythos show up in none of the misuse cases, with a single exception from the distillation chapter.

The finding

Anthropic puts it best itself: «Sophisticated attacks no longer require sophisticated attackers.» A hacktivist with stolen API keys, a handful of financially motivated individuals and a state espionage operator each ran campaigns against many victims at once – campaigns that a year ago would have needed a team.

The techniques themselves are dull: stolen credentials, unpatched edge devices, exposed services, SQL injection, phishing. None of it is new. What changed is the arithmetic behind it. Recon, exploitation, tooling, data processing – the labour that used to separate well-resourced groups from everyone else now runs in harnesses, in parallel, at machine speed.

Three numbers that make it concrete

One French-speaking operator in the ShinyHunters orbit ran a credential pipeline across ten AWS EC2 workers. It bulk-downloaded 1.8 million Android APKs, decompiled them and scanned for hardcoded secrets with TruffleHog. Verified hits went straight into a Telegram group, sorted across more than 100 source types.

Another affiliate breached a SaaS provider and used that foothold to reach data belonging to roughly 200 downstream customers. Then it pulled over 2,100 Azure AD token sets from more than 40 corporate tenants in about 34 hours. Anthropic’s note on that one: «AI agents performed nearly all of the work.»

Among the influence operations, one case stands out for not being based in Moscow or Tehran. Behind a network of about 70 fabricated news sites, 70 matching X accounts and more than 250 sockpuppet commenting accounts sits LKM Company, a digital advertising agency in France. At least 8,913 articles in around 20 languages, political stance depending on who was paying.

Autonomy is not the same as harm

The report makes this point explicitly, and it matters. The most serious compromises described here came from operations where a human directed every step. Autonomy drives cost down and volume up. It does not automatically raise the damage per case.

In plain economic terms: targets that used to be not worth attacking are worth attacking now. Not because the payoff grew, but because the effort shrank.

Why I read these

Threat reports from model vendors have an obvious problem. The vendor reports on itself and decides what goes in. Even so, they’re currently the only place where someone with real telemetry writes down how attackers actually use these tools. No government has that view.

The case that stayed with me isn’t the Russian one. It’s the French ad agency with 8,913 articles.

Sources: Anthropic: Detecting and countering misuse of AI, September 2026 · Techmeme: Anthropic publishes a threat intelligence report

AnthropicSecurityClaudeMisuse