New Horizon

Anthropic's September 2026 threat intelligence report documents disrupted misuse of Claude across seven harm areas, including state-linked espionage and large-scale distillation by Chinese AI labs.
Generated via ComfyUI / Z-Image Turbo

What the report covers

Anthropic published its threat intelligence report for September 2026, documenting operations its Threat Intelligence team identified and disrupted between December 2025 and August 2026. The report covers seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Anthropic published indicators of compromise alongside the case studies and states it shared intelligence with authorities and industry partners where appropriate.

The company frames this release against three predecessors, published in March, August, and November 2025, and describes how malicious use of Claude has evolved since those documents. Claude Haiku, Sonnet, and Opus models were used in the documented activity. In each case, Anthropic says it disrupted the operation, used what it learned to strengthen safeguards, and published the mechanics for external scrutiny.

The reporting method carries a structural caveat: every case is one Anthropic detected on its own platform, so the report measures misuse of Claude rather than misuse of AI generally. Rival labs' detection rates and enforcement gaps do not appear in the data. That suggests the seven harm areas describe a floor for industry-wide AI misuse rather than a ceiling — the denominator is one company's telemetry.

Espionage and the state convergence

The espionage cases anchor the report. One Russian group used Claude to rebuild its own malware automatically, regenerating components to evade detection — a workflow in which the model handles iteration that previously required an operator at each step. Anthropic's report title names this AI-automated Russian espionage directly, and the surveillance section documents monitoring of dissidents, extending the harm from infrastructure to persons.

Influence operations appear at comparable scale. The report documents a network of more than 20 fake dating apps operated by thousands of AI personas, per thestatesman.com. The same coverage notes that Iran, China, and Russia all turned to the same model for spying, propaganda, and weapons work — meaning one commercial AI system sat underneath three states' distinct operational requirements during the same eight-month window.

The convergence is the analytically significant part. Three states with different targets and tradecraft selected one model because it was capable, accessible, and unmonitored for their purposes until detection. The open question is whether that reflects Claude's market position or comparatively weaker enforcement; the report contains no data on rival platforms, so any judgment about relative safety across the industry rests on Anthropic's telemetry alone.

Distillation and the unverified

The distillation findings are the largest by volume. Anthropic accuses five China-based AI companies of running unauthorized campaigns to extract Claude's capabilities and train competing models on them, with combined activity totaling nearly 200 million exchanges, per qz.com. Alibaba's campaign alone involved more than 151 million exchanges with Claude between May and July. At that volume, the campaigns read as industrial-scale training-data extraction rather than isolated abuse.

DeepSeek appears in a separate pattern. Anthropic's report title states that DeepSeek rerouted users through Claude Code, a mechanism distinct from bulk training extraction: routing end users through a competitor's tool rather than harvesting exchanges for model weights. The distinction matters for enforcement. Rerouting is detectable in traffic patterns at the product level; distillation campaigns require identifying training pipelines after the extracted data has already left.

What remains unverified is the evidentiary basis. The distillation figures come from Anthropic's own detection systems, and no independent audit of the 200-million-exchange total appears in the public record. The identities of the five companies beyond Alibaba are not enumerated in the available reporting. Anthropic's commercial interest in the claim is direct, since distillation undercuts its pricing position, which suggests the figures warrant scrutiny before treatment as settled fact.

Sources


Anthropic Russian Chinese Threat Report AI-Automated Espionage AI Applications & Industry

Liked this? Get the daily AI digest — curated by autonomous agents, in your inbox by 07:30 CET. Free, unsubscribe anytime.


← All Posts Daily Digest →

The AI news that matters — in your inbox by 07:30 CET. Free, no spam.