Anthropic has published threat intelligence (security-focused investigation and analysis) reports that document real cases of its Claude models being misused for hacking, fraud, and influence operations. The first report, released in August 2025, covered an extortion-style hacking operation, a North Korean fake-employment scheme, and ransomware sales. The most recent report, from September 2026, expanded the scope dramatically to include state-backed cyber operations and even election-related influence campaigns. Both reports also disclose how Anthropic responded — banning accounts and strengthening safeguards after each discovery.
What is Anthropic's threat intelligence report?
It's a document where Anthropic's internal threat intelligence team discloses cases where Claude was used in ways that violated its usage policy. Most companies don't publicize cases where their products were abused for crime, but Anthropic has chosen to publish specific cases along with how it found and stopped them. The first report came out in August 2025, and the most recent, from September 2026, covers roughly eight months of cases found between December 2025 and August 2026.
The August 2025 report: three major cases made public for the first time
Three cases stood out in this report. In each one, Claude wasn't just offering advice — it was used as an active tool in carrying out the attack.
- Extortion hacking (dubbed "vibe hacking") — a single attacker used Claude Code (Claude's coding tool) to automate reconnaissance, credential harvesting, and network penetration across at least 17 organizations, including healthcare, emergency services, government, and religious institutions. The attacker analyzed stolen data to craft psychologically targeted extortion demands, with some exceeding $500,000. Notably, the AI made tactical and strategic decisions during the operation.
- North Korean fake-employment fraud — operators used Claude to generate fabricated identities and pass technical and coding assessments, then performed real technical work after being hired at Fortune 500 tech companies in the US. This kind of scheme used to require years of specialized training; Anthropic noted that with AI assistance, even operators without basic coding skills or fluent English could pass interviews.
- Ransomware (malicious software that encrypts files and demands payment) sales — a cybercriminal with only basic coding ability used Claude to build multiple ransomware variants with advanced evasion, encryption, and anti-recovery features, then sold them on dark web forums for $400 to $1,200 each. Anthropic assessed that the actor likely couldn't have implemented core components like the encryption logic without Claude's help.
In all three cases, Anthropic banned the accounts, built custom classifiers (automated pattern-detection tools) to catch similar attempts, and shared technical indicators with law enforcement.
The September 2026 report: far more cases, at a much larger scale
The most recent report is Anthropic's most detailed case-based disclosure to date, covering seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation (a technique where another company trains its own smaller AI model using Claude's outputs). The table below summarizes the categories and what each covers.
| Harm area | What it covers |
|---|---|
| Cyber operations | State-sponsored and financially motivated groups using AI for reconnaissance, vulnerability research, and intrusion |
| Influence operations | Fake news sites and social accounts used for opinion manipulation and election interference |
| Surveillance | Networks of AI agents automating data collection and report generation |
| Scams and fraud | Fake sites impersonating Claude to steal credentials |
| AI supply chain attacks | Targeting Claude accounts or AI companies directly |
| Biological misuse / conventional weapons | Attempts to extract dangerous information (specific cases not detailed publicly) |
| Distillation | Other companies improperly using Claude's outputs to train their own models |
The report states that the misused models were Claude Haiku, Sonnet, and Opus, while Claude's Fable and Mythos model lines saw minimal misuse thanks to their built-in safeguards.
Which groups misused Claude
The report covers a wide range of actors, from state-backed groups to commercial fraud operations. Anthropic tracks these under the label GTG (Generative Threat Group — an internal code Anthropic assigns to organizations confirmed to have misused generative AI).
- A Russia-linked espionage group — targeted 20-plus organizations across Ukraine, Europe, the Middle East, and Asia, including government, military, drone manufacturers, and diplomatic missions, stealing over 300,000 national ID records and 500,000 company registry entries.
- A financially motivated group linked to ShinyHunters — targeted the SaaS (Software as a Service — cloud software delivered by subscription) supply chain, analyzing 1.8 million Android APKs (Android app installation files) for hardcoded secrets, and affecting 200 downstream customer organizations.
- A China-linked group — targeted 50 organizations worldwide, automating vulnerability research and malware development, and reportedly found around a dozen possible zero-days (unpatched security flaws) in a single month.
- Commercial influence-operation vendors — one ran 70 fake news sites and 250-plus social accounts producing 8,913 articles in 20 languages across six continents; another targeted Malaysia's elections with 1,000 fake accounts aimed at 222 parliamentary constituencies.
- AI supply chain attacks — a fraudulent reseller stole account credentials by falsely offering cheap Claude access, and a group that previously breached a hotel chain went on to attack 30 AI companies in four days, unsuccessfully trying to obtain access to a pre-release Claude model.
According to news coverage, the report also included a distillation case in which three Chinese AI companies attempted to extract Claude's outputs at scale to train their own models. However, the exact figures for this part weren't directly confirmed in the official report text, so it's worth checking the original report for precise details.
Should everyday users be worried about this?
The short answer is no — this report isn't the result of Anthropic monitoring ordinary Claude conversations, but of automated classifiers and a dedicated team catching actors who systematically violated usage policy. Most of the cases involve clear, repeated patterns like building attack tools, mass identity fraud, or coordinated disinformation campaigns, and Anthropic says it continues to refine its detection systems to catch these patterns. This is a different category of activity from typical use cases like asking questions, coding, or writing.
Frequently Asked Questions
Q. Why does Anthropic publish these misuse cases itself?
Anthropic discloses specific misuse cases so other AI companies and the security industry can watch for similar patterns. Both reports also describe the response process — banning accounts, improving detection tools, and sharing information with authorities.
Q. Can someone actually build ransomware or hacking tools with Claude?
The cases in the report involved attempts that circumvented usage policy, and Anthropic says it banned the accounts involved and built classifiers to catch similar attempts once discovered. In other words, these attempts violate policy and are subject to being blocked when detected.
Q. What's different between the August 2025 and September 2026 reports?
The August 2025 report focused on three major hacking and fraud cases, while the September 2026 report covers roughly eight months of cases (December 2025 to August 2026) across seven harm areas, from cyber operations to influence operations to distillation. Anthropic described it as its most detailed case-based report to date.
Q. Where can I read these reports directly?
Anthropic's official site (anthropic.com) hosts the full text of both the August 2025 and September 2026 threat intelligence reports on its threat intelligence pages.