Blog Network

Anthropic · 2026-09-10 · major

Anthropic threat report — attackers now let Claude run whole intrusions

Anthropic's September 2026 threat intelligence report covers eight months of disrupted misuse of Claude across seven harm categories, including a Russian espionage group that automated intrusions against more than 20 organisations.

Anthropic threat intelligence report cover art, September 2026

Anthropic's Threat Intelligence team names four cyber groups that let Claude plan and carry out intrusions end to end.

Key specs

Fake articles in one influence op8,913
Ai companies probed in four days~30

Quick facts

PublisherAnthropic Threat Intelligence team
Period coveredDecember 2025 - August 2026
Harm categories7
Largest cyber caseGTG-10007, roughly 50 organisations targeted
Published for defendersIndicators of compromise plus a full PDF
ResponseAccounts banned, new detections, intelligence shared

What is it?

Four named cyber operations anchor Anthropic's September 2026 threat intelligence report, which documents misuse of Claude that the company found and disrupted between December 2025 and August 2026. The report sorts the activity into seven harm categories: cyber operations, surveillance, influence operations, conventional weapons, biological misuse, scams and fraud, and illicit distillation.

How does it work?

The pattern the report calls "vibe hacking" runs through the cyber cases: an operator gives the model a general goal, then lets it survey the environment, write and run scripts, summarise what it found, and repeat until the task is done. GTG-10007, a Chinese exploit-foundry cluster, ran agent swarms doing reconnaissance in parallel and surfaced more than a dozen possible zero-day findings in a single month. GTG-20006 automated a Russian espionage workflow from tool development through data exfiltration.

Why does it matter?

One case in the report targets the AI supply chain itself. GTG-50020 injected malicious instructions into an AI vendor's automated evaluation sandbox to lift production API keys from several providers, then probed roughly thirty AI companies in about four days looking for pre-release Claude access — an attempt Anthropic says failed. Alongside the case studies, Anthropic publishes indicators of compromise so defenders can hunt for the same activity in their own logs.

Who is it for?

security teams and threat intelligence analysts

Frequently asked questions

Did any attacker get access to unreleased Claude models?
No. Anthropic's report says GTG-50020, a Russian-speaking group, compromised an AI vendor's evaluation sandbox to steal production API keys from multiple providers and then targeted roughly thirty AI companies in about four days specifically seeking pre-release Claude access. Anthropic states the attempt to reach unreleased models was ultimately unsuccessful.
What indicators of compromise did Anthropic publish?
The Anthropic report ships domains, IP addresses, email addresses and file hashes, plus Telegram bot and group IDs with descriptions and attacker egress IP ranges with date windows. It names malware including PowerChrome, WUEngine, DarkSword and GiftDrop. A downloadable PDF carries the full list for defenders to load into detection tooling.
How does this differ from Anthropic's August 2025 threat report?
Anthropic's August 2025 report walked through three cases: a Claude Code extortion campaign against 17-plus organisations, North Korean employment fraud, and ransomware sold by a low-skill criminal. The September 2026 report spans eight months and seven harm categories, and the new pattern is scale — agent swarms running parallel reconnaissance and attacks aimed at AI providers themselves.
How large were the influence operations described?
Two influence clusters stand out in Anthropic's report. GTG-54002 published at least 8,913 articles in about 20 languages across 70 fake news websites, backed by more than 250 inauthentic commenting accounts. GTG-84005 ran over 1,000 fake X accounts and asked for one million artificial views on its content.
What did Anthropic do about the accounts it found?
Anthropic banned the accounts tied to every identified threat actor, deployed extra monitoring to catch related activity, and strengthened its safeguards based on what the investigations turned up. The company also shared intelligence with authorities and industry partners, and built automated detections that key on the behavioural signatures of the disrupted operations.

Sources · 2 outlets

Tags

  • anthropic
  • claude
  • threat-intelligence
  • cybersecurity
  • ai-misuse
  • influence-operations
  • indicators-of-compromise
  • agentic-ai
  • supply-chain-security

← All releases