Anthropic · 2026-09-10 · major
Anthropic threat report — attackers now let Claude run whole intrusions
Anthropic's September 2026 threat intelligence report covers eight months of disrupted misuse of Claude across seven harm categories, including a Russian espionage group that automated intrusions against more than 20 organisations.

Anthropic's Threat Intelligence team names four cyber groups that let Claude plan and carry out intrusions end to end.
Key specs
| Fake articles in one influence op | 8,913 |
|---|---|
| Ai companies probed in four days | ~30 |
Quick facts
| Publisher | Anthropic Threat Intelligence team |
|---|---|
| Period covered | December 2025 - August 2026 |
| Harm categories | 7 |
| Largest cyber case | GTG-10007, roughly 50 organisations targeted |
| Published for defenders | Indicators of compromise plus a full PDF |
| Response | Accounts banned, new detections, intelligence shared |
What is it?
Four named cyber operations anchor Anthropic's September 2026 threat intelligence report, which documents misuse of Claude that the company found and disrupted between December 2025 and August 2026. The report sorts the activity into seven harm categories: cyber operations, surveillance, influence operations, conventional weapons, biological misuse, scams and fraud, and illicit distillation.
How does it work?
The pattern the report calls "vibe hacking" runs through the cyber cases: an operator gives the model a general goal, then lets it survey the environment, write and run scripts, summarise what it found, and repeat until the task is done. GTG-10007, a Chinese exploit-foundry cluster, ran agent swarms doing reconnaissance in parallel and surfaced more than a dozen possible zero-day findings in a single month. GTG-20006 automated a Russian espionage workflow from tool development through data exfiltration.
Why does it matter?
One case in the report targets the AI supply chain itself. GTG-50020 injected malicious instructions into an AI vendor's automated evaluation sandbox to lift production API keys from several providers, then probed roughly thirty AI companies in about four days looking for pre-release Claude access — an attempt Anthropic says failed. Alongside the case studies, Anthropic publishes indicators of compromise so defenders can hunt for the same activity in their own logs.
Who is it for?
security teams and threat intelligence analysts
Frequently asked questions
- Did any attacker get access to unreleased Claude models?
- No. Anthropic's report says GTG-50020, a Russian-speaking group, compromised an AI vendor's evaluation sandbox to steal production API keys from multiple providers and then targeted roughly thirty AI companies in about four days specifically seeking pre-release Claude access. Anthropic states the attempt to reach unreleased models was ultimately unsuccessful.
- What indicators of compromise did Anthropic publish?
- The Anthropic report ships domains, IP addresses, email addresses and file hashes, plus Telegram bot and group IDs with descriptions and attacker egress IP ranges with date windows. It names malware including PowerChrome, WUEngine, DarkSword and GiftDrop. A downloadable PDF carries the full list for defenders to load into detection tooling.
- How does this differ from Anthropic's August 2025 threat report?
- Anthropic's August 2025 report walked through three cases: a Claude Code extortion campaign against 17-plus organisations, North Korean employment fraud, and ransomware sold by a low-skill criminal. The September 2026 report spans eight months and seven harm categories, and the new pattern is scale — agent swarms running parallel reconnaissance and attacks aimed at AI providers themselves.
- How large were the influence operations described?
- Two influence clusters stand out in Anthropic's report. GTG-54002 published at least 8,913 articles in about 20 languages across 70 fake news websites, backed by more than 250 inauthentic commenting accounts. GTG-84005 ran over 1,000 fake X accounts and asked for one million artificial views on its content.
- What did Anthropic do about the accounts it found?
- Anthropic banned the accounts tied to every identified threat actor, deployed extra monitoring to catch related activity, and strengthened its safeguards based on what the investigations turned up. The company also shared intelligence with authorities and industry partners, and built automated detections that key on the behavioural signatures of the disrupted operations.