Anthropic says its Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity over the past eight months, and it published the account on September 10 in a report titled Detecting and countering misuse of AI: September 2026. The coverage window runs from December 2025 to August 2026, and the report sorts the cases into seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation, the practice of extracting one model's outputs to train another (full report page).
The awkward part is that this is a company's own account of what it caught. Anthropic says that in each case it disrupted the activity, used what it learned to strengthen its safeguards, and shared intelligence with authorities and industry partners where appropriate. There is no outside audit in the document, so the cases describe Anthropic's detection reach as much as they describe the attackers.
Anthropic names the actors, not only the tools
The report says the threat actors it covers include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions and politically motivated individuals. The range matters: these are not all sophisticated state programs. The cases run from a network of fake dating apps built to defraud users to surveillance systems built to identify and monitor dissidents.
Reuters reported that Anthropic broke up attempts to use Claude both to support biological weapons development and to run a suspected Russia-linked cyber espionage campaign against Ukraine.
Two cases show how much one operator can now do
A separate Iran-linked account used Claude to gather and analyze publicly available information and build targeting recommendations against US naval forces in the region, compiling targeting handbooks and tracking naval positions from open sources, according to Iran International's reading of the report.
On the surveillance side, the report says that between January and July it disrupted operations in which state-aligned actors, state-linked contractors and commercial spyware vendors used Claude to build and run surveillance systems, including actors from China, Iran and West Africa, plus the commercial surveillance-for-hire market. One illustration involves a single consultant in Mali whose platform reached about 25 million SIM cards across all three mobile operators and generated dossiers without a warrant. One person, built at the scale of a national system.
Weapons and biology are where the report is most careful
Anthropic reports six cases where Claude was used to write software for conventional weapons and targeting or control systems, including firearms, missiles and armed drones. In one, Claude Code wrote guidance, navigation and control software for three weapons programs, among them a guided rocket. Software for a missile's steering is a narrow, well-bounded task, which is exactly the kind an assistant model can help with even without any weapons-specific training.
The report also documents five examples of scientists using the models in ways that could support biological weapons development, and Reuters notes Anthropic's own framing there is cautious. Anthropic says it does not assert those scientists intended harm, and experts disagree about whether the work was dangerous or ordinary pathogen research. Anthropic's head of threat intelligence, Jacob Klein, called it an incredibly nuanced situation.
What the report does not settle
One number deserves care. Several outlets count 39 case studies across the seven areas, but that total does not appear on Anthropic's own report page, which says only that it shares case studies from the operations it disrupted. Treat 39 as a secondary count, not an Anthropic figure, until the company states it.
The models involved were Claude Haiku, Sonnet and Opus. Anthropic says none of the cases involved the Fable or Mythos-class models, with a single exception in the one illicit distillation case.
Why it matters
The report's central claim is blunt: "Sophisticated attacks no longer require sophisticated attackers," as carried in ANI's account of the report. A secondary analysis, by Kai Magnus on Daniel Miessler's site, argues that AI has narrowed the labor and tooling gap between lone operators and state teams.
That has a practical consequence for anyone defending systems. If a single consultant can reach 25 million SIM cards and a small team can write missile guidance code with an assistant, then technical sophistication becomes a weaker signal of who is behind an attack. Attribution habits built for a world of well-resourced state groups may not fit the current mix of lone actors, contractors and propaganda shops. The same erosion runs the other way too: detection, review and disclosure now carry more of the weight that human expertise used to carry.
Which matters more right now: tightening what these models will help with, or building the detection capacity to catch misuse that gets through?