World

How Hackers, Spies and Criminals Used Claude — and How Anthropic Stopped Them

Elena MarquezPublished 12h ago6 min readBased on 7 sources
Reading level
How Hackers, Spies and Criminals Used Claude — and How Anthropic Stopped Them
Photo by TechCrunch / CC BY 2.0

Anthropic says it shut down a series of operations in which suspected state-linked groups, profit-driven criminals and politically motivated individuals used Claude to support hacking, spying and weapons-related work.

The findings appear in a September 2026 report titled "Detecting and countering misuse of AI: September 2026". Anthropic said its Threat Intelligence team found and stopped the activity in the six months before the report. The hacking cases covered run from December 2025 through August 2026. Anthropic

The report covers seven areas of harm, from cyber operations to biological misuse. Influence operations and surveillance are two of the seven. Anthropic also documented disruption of bioweapons research efforts involving Claude, as well as Russian hacking activity and Chinese misuse of Claude models. Reuters Separately, Anthropic said several actors had used its Claude AI models for activities including weapons, spying and cyber operations. Reuters

For tracking, Anthropic uses Generative Threat Groups (GTGs). The term is an internal label for actors seen abusing AI, much like a case number for investigators. It defines uplift as the boost AI provides, or how much more harm was done with AI than without it, measured in speed, scale and depth.

Autonomous operations become standard

In November 2025, Anthropic documented an operating model used by a suspected state-sponsored campaign to carry out attacks with little human guidance. In the September 2026 report, it assessed that the model had spread across every class of actors investigated.

The timeline is compressed. Publicly available attack tools like PentAGI reproduce much of the same setup for automating each step of the cyber kill chain, the sequence from scouting a target to breaking in to delivering a payload. Anthropic assessed that more actors, from lone individuals to organized groups, will continue to adopt AI frameworks to enable more skilled attacks at greater speed and scale as models evolve.

That assessment builds on earlier disclosures. Anthropic published a report titled "Disrupting an AI-orchestrated cyber espionage campaign" about a complex AI-led spying attack and its disruption on Nov. 13, 2025. Its August 2025 Threat Intelligence report discusses Claude misuse cases including a large-scale extortion operation. Anthropic

Models, safeguards and disruption playbook

In all cases in the September 2026 report, Claude Haiku, Sonnet and Opus models were used. No malicious activity was found on Claude Fable or Mythos. Anthropic said Claude Mythos has safeguards in place that greatly reduce its ability to perform harmful cyber tasks.

Anthropic announced Claude Fable 5.1 and Claude Mythos 5.1 on Sept. 1, 2026. It described the releases as its most advanced models for coding and knowledge work.

In each disrupted case, Anthropic said it disrupted the activity, strengthened AI safeguards based on what it learned, and shared intelligence with authorities and industry partners where appropriate. The formula is consistent. Detection leads to account-level action, then to control updates informed by observed tactics.

Geopolitical fallout

The broader context here is that attributions naming Russia and China, plus bioweapons-related research, give a company safety report weight in state-level competition. It places technical findings inside a larger struggle over capabilities and norms.

A Chinese state newspaper branded Anthropic CEO Dario Amodei's call to slow AI development a "Cold War playbook" targeting China. Reuters

In my view, the operational detail matters more than the labels for practitioners. Threat labels like GTGs are built for internal tracking and sharing among companies. Once they appear alongside country names and weapons claims, capitals read them as political signals, whatever the technical intent was.

Looking at what this means for defense, the shift from human-typed prompts to automated setups changes the costs of intrusion, scouting and payload building. Speed shortens defender reaction time. Scale lets smaller teams run parallel campaigns. Depth extends reach into later stages of the kill chain that once required specialized skill.

Looking ahead to the next reporting cycle, the report points to three priorities and one open question. First, detection must account for agent frameworks, not only single-model prompts. Second, safeguards tuned to Haiku, Sonnet and Opus abuse patterns may need revalidation with each capability jump, including Fable and Mythos lineage systems. Third, sharing with authorities and industry partners will shape whether similar tooling is caught early elsewhere or met as a new intrusion set. Anthropic expects continued uptake across actor types. Whether safeguards, sharing and law enforcement disruption slow that curve will determine if autonomous operations remain an edge for well-resourced teams or become baseline tradecraft.