Anthropic · Friday, September 11, 2026
Anthropic details how people tried to misuse Claude
The File desk · Sep 11, 2026, 10:18 AM UTC
Status
Confirmed from Anthropic’s company threat report dated Sept. 10, 2026. Actor attributions, including a Midnight Blizzard link, are Anthropic’s. Outside labs and governments have not been independently verified here as confirming every attribution.
- Confirmed
Anthropic’s Threat Intelligence team said that over about eight months it found and shut down operations that tried to use Claude for harm. The report covers December 2025 through August 2026 in seven areas. Claude Haiku, Sonnet, and Opus models show up in the cases. Anthropic says none of the misuse cases involved Claude Fable or Mythos-class models except one illicit distillation case. The company says it banned accounts, hardened safeguards, and shared intelligence with authorities and industry partners.
- Unverified
Anthropic’s labels for actors — including a Russian-speaking operator it ties to Midnight Blizzard-style espionage, and a cluster it ties to suspected ShinyHunters affiliates — are the company’s. Outside labs and governments have not been independently verified here as confirming every attribution.
Anthropic put a long threat report on the table Thursday. The company’s Threat Intelligence team says that over about eight months it found and shut down operations that tried to use Claude for harm. The report covers activity from December 2025 through August 2026 in seven areas: cyber attacks, influence campaigns, surveillance, scams and fraud, biological misuse, conventional weapons work, and illicit distillation. Claude Haiku, Sonnet, and Opus models show up in the cases. Anthropic says none of the misuse cases involved Claude Fable or Mythos-class models except one illicit distillation case. The actors range from suspected state-backed groups to money-motivated criminals, spyware vendors, state propaganda shops, and politically motivated individuals. One detailed cyber case, labeled GTG-20006, describes a Russian-speaking operator whose tradecraft the company says is consistent with Midnight Blizzard-style espionage against Ukrainian and European government and defense targets. Another cluster, tied to suspected ShinyHunters affiliates, used Claude to speed smash-and-grab data theft and extortion. Anthropic says it banned accounts, hardened safeguards, and shared intelligence with authorities and industry partners. Outside labs and governments have not been independently verified here as confirming every attribution.
Anthropic put a long threat report on the table Thursday.
The company’s Threat Intelligence team says that over about eight months it found and shut down operations that tried to use Claude for harm.
The report covers December 2025 through August 2026. It groups the work into seven areas: cyber attacks, influence campaigns, surveillance, scams and fraud, biological misuse, conventional weapons work, and illicit distillation.
Claude Haiku, Sonnet, and Opus models show up in the cases. Anthropic says none of the misuse involved Claude Fable or Mythos-class models, except one illicit distillation case.
The people it describes range from suspected state-backed groups to money-motivated criminals, commercial spyware vendors, state propaganda shops, and politically motivated individuals.
One cyber case, labeled GTG-20006, describes a Russian-speaking operator. Anthropic says the tradecraft matches Midnight Blizzard-style espionage against Ukrainian and European government and defense targets.
Another cluster, which the company ties to suspected ShinyHunters affiliates, used Claude to speed smash-and-grab data theft and extortion. Anthropic says it banned those accounts.
The company says it hardened safeguards and shared intelligence with authorities and industry partners. The attributions are Anthropic’s. This desk has not independently verified them.
What is still unknown or disputed
- Independent confirmation of actor attributions, including Midnight Blizzard links, is not established by this desk beyond Anthropic’s report.
- Victim identities and full impact totals for every case are not independently verified here.
Primary sources
Every claim in this story is drawn from the documents below. If a fetch failed, that is recorded on the card.
Source 1
Detecting and countering misuse of AI: September 2026
Anthropic · September 10, 2026
Threat Intelligence identified and disrupted operations using Claude for malicious activity Dec. 2025–Aug. 2026 across seven harm areas. Claude Haiku, Sonnet, and Opus were used. None of the misuse cases involved Claude Fable or Mythos-class models except one illicit distillation case.
https://www.anthropic.com/threat-intelligence-report-september-2026