Imagine waking up to find that an online attack targeting your company didn’t need a team of hackers staring at screens at 3 a.m. Instead, an artificial intelligence quietly scoured the internet for weaknesses, slipped through a security gap, collected sensitive data, and covered its tracks—all while a single operator sipped coffee and reviewed the results. That is the new reality described in a sweeping report from Anthropic, the AI company behind the Claude chatbot family. For years, the fear was that AI would help bad actors write malicious code or explain how to build a bomb. The company’s fourth threat intelligence report, Detecting and Countering Misuse of AI: September 2026, paints a far more unsettling picture: AI is no longer just a helper. It is increasingly running whole operations by itself—finding targets, breaking into systems, generating disinformation, even adapting its own code to evade security software. Between December 2025 and August 2026, Anthropic says it identified and disrupted attempts to use Claude for cyberattacks, espionage, surveillance, scams, influence operations, and weapons-related research. The actors behind these efforts range from suspected state-sponsored groups and criminals to commercial spyware companies, propaganda operations, and politically motivated individuals. The report runs 154 pages and is dense with technical detail, but the human story beneath it is simple: AI is changing who can cause harm, how much harm they can cause, and how little effort it now takes.
One of the most striking cases in the report involves a Chinese-speaking espionage group that Anthropic believes was likely based in Changsha, in China’s Hunan province. This was not a lone hacker fumbling with stolen tools. The group used Claude as an active participant in a broad operation targeting around fifty organizations—companies and government agencies spanning education, healthcare, finance, energy, and technology. According to Anthropic, the attackers stole hundreds of megabytes of student data from an education technology company, broke into a retail company’s systems, and obtained citizen records from a Southeast Asian government agency, including names, phone numbers, and home addresses. But what makes this case particularly alarming is how much of the work was handed off to AI. The attackers used Claude not just to write code, but to study security products for weaknesses and develop ways to exploit them. They connected the AI to other software, allowing it to handle several stages of the attack at once: finding potential targets, identifying vulnerabilities, stealing information, and processing it. In some cases, multiple AI systems worked in parallel on different tasks, with humans setting broad objectives and checking the results. Anthropic notes that this kind of automation can make sophisticated attacks possible with far fewer people and much less technical expertise than would traditionally have been required. What once demanded a skilled team of hackers can now be attempted by a small group—or even a single person—with the right AI tools and a vague sense of what they want to accomplish.
The report also exposes how AI is being used to manipulate public opinion on a massive scale, often in ways that are cheaper and faster than ever before. Anthropic identified an automated fake-news operation in Bangladesh that used Claude to generate Bengali-language content supporting the Awami League and attacking its political opponents. What stands out is the sheer productivity of a single person. According to Anthropic, one actor used 29 Claude accounts to generate at least 1,500 headlines, 300 fabricated stories, and 1,500 image prompts. The material was designed for Facebook, YouTube, and TikTok videos aimed at rural audiences—especially people with limited literacy, who might not immediately recognize false information. The actor’s own messages reportedly described the material as “fake news” and instructed that it should be “hot and aggressive” while staying simple enough for village audiences to understand. The fabricated stories attacked the Bangladesh Nationalist Party, Jamaat-e-Islami, the National Citizens Committee, the interim government, and student protest leaders. Anthropic stressed that it found no evidence the Awami League itself directed or funded the operation, and although some narratives aligned with pro-Indian geopolitical interests, there was no proof of state involvement. But the automation is the real story. AI generated the text, other software turned it into videos, and scheduling tools published it—all with minimal human effort. This kind of operation used to require a newsroom of propagandists, graphics designers, and social media managers. Now it can be run by one determined person with a handful of accounts and a willingness to mislead. It is a glimpse of a future where disinformation is not just abundant but customized, synthesized in real time to appeal to specific communities, and distributed across platforms before fact-checkers can even identify the source.
Beyond espionage and disinformation, Anthropic found evidence that AI is being woven into cyberattacks in ways that make them harder to stop. The report describes a group whose activity was consistent with Midnight Blizzard, a Russia-linked hacking team known for sophisticated intrusions. This group used Claude to help its malware avoid detection. According to Anthropic, the system could reportedly identify when security software had noticed the malware, then modify the malware to slip past those defenses—essentially giving the attack a self-preservation instinct. The group targeted military intelligence organizations, government agencies, diplomatic bodies, and defense-related companies, using AI at several stages of the operation, from finding targets and maintaining access to stolen systems to exfiltrating information. Similar patterns appeared elsewhere. Iranian actors developed a system capable of identifying people through their social media accounts, pointing toward a future of automated surveillance. In another case, a contractor working for Malian national security authorities allegedly used Claude to develop software for an intelligence-gathering operation. Anthropic says these cases point to a broader shift: AI is increasingly being used “in place of an engineering workforce.” That phrase deserves attention. In the past, conducting surveillance or adapting malware required skilled programmers and analysts. Now, AI can perform those roles, meaning state-linked groups and even smaller actors can expand their capabilities without hiring experts. The report also raises concerns about weapons-related research. Anthropic identified five cases where people used Claude in ways that could potentially support biological weapons development—including work involving chikungunya, a highly pathogenic strain of avian influenza, virus families that include smallpox and mpox, and venoms and toxins. The company cautiously noted that the people involved were working scientists, and it was not claiming they intended to cause harm. But it acknowledged that biological research is uniquely hard to assess because the same information that could help build a weapon could also help develop vaccines or treatments. Separately, Anthropic found six cases in which Claude was used to develop software for conventional weapons—firearms, missiles, armed drones, and bombs—as well as systems used to control or target them.
Perhaps the most surprising section of the report is not about cyberattacks or disinformation, but about corporate competition—specifically, the lengths some companies will go to copy another’s AI. Anthropic accused operators affiliated with the Chinese technology company Alibaba of carrying out the largest attempt to replicate Claude’s capabilities it has ever measured. The technique, called distillation, works by repeatedly asking one AI model questions and using its answers to train another model. Alibaba’s campaign, according to Anhtropic, focused on Claude’s ability to reason through difficult tasks, and the responses were used to improve Alibaba’s Qwen AI models. The scale is staggering: the campaign peaked at nearly three million exchanges in a single day, involved more than 3,500 fraudulent accounts, and between May and July 2026, Anthropic recorded more than 151 million exchanges it attributed to Alibaba’s activity. Requests focused on software development, AI agents, and other tasks requiring complex reasoning. Anthropic also alleged that Alibaba used Claude to help with its own AI research, including work on systems used to train its models. When Anthropic blocked the initial wave of fraudulent accounts—which were disguised using disposable email addresses and virtual payment cards—Alibaba apparently shifted to another group of accounts. Nor was Alibaba alone. Anthropic accused Chinese AI firms Moonshot and DeepSeek of using Claude’s outputs in similar attempts to improve their own models. In Moonshot’s case, nearly 300,000 customer requests were sent to Anthropic’s systems over ten days through a network of 5,380 allegedly fraudulent accounts. Some of those requests may have contained sensitive customer information, raising concerns about whether users even knew their data was being routed through a third party. This is not the classic story of malicious hackers trying to steal secrets. It is a story of AI companies, hungry for an edge, treating another company’s product as a free tutor—and exposing their own users’ data in the process.
The deeper message of Anthropic’s report is captured in a term the company uses: “uplift.” It refers to how much faster, larger, or more effective an operation becomes with AI. In some cases, AI does not just make attacks slightly better; it makes them possible at all for actors who lack traditional expertise. Anhtropic is careful to say the cases in the report are not necessarily representative of everyday misuse—they are among the more significant or unusual incidents identified by its threat intelligence team. But the trend is clear. AI is increasingly connected to other software, given tools, and allowed to act autonomously within broad human instructions. The challenge for AI companies, the report suggests, is no longer only preventing models from directly providing harmful information. It is understanding how increasingly capable AI systems can be combined with other tools to carry out real-world operations with limited human involvement. Anthropic says it has incorporated its findings into its processes to better prevent, detect, and disrupt similar activities in the future, and has shared intelligence with authorities and industry partners. The report arrives amid growing warnings from AI researchers and industry leaders about the risks of increasingly capable systems. An Anthropic engineer, Jacob Coxon, recently resigned after warning that AI could pose an extreme risk to humanity—including, in a worst-case scenario, the possibility of AI killing everyone by the end of the decade. An Anhtropic safety researcher has also warned of catastrophic harm, and OpenAI’s chief scientist has called for voluntary slowdowns until safeguards exist. But while those debates focus on hypothetical futures, this report documents harms already unfolding. AI is being used to automate cyberattacks, produce political disinformation, conduct surveillance, support weapons-related work, and potentially assist dangerous biological research. The technology is not waiting for the future. It is already woven into the quiet, unglamorous machinery of modern threats—turning the lonely work of hackers, propagandists, and spies into something faster, broader, and more humanly detached than ever before.

