Anthropic foils AI misuse for cyber, bio threats

Amid the ongoing debate over the misuse of Artificial Intelligence (AI), Anthropic has released a report detailing how it has blocked efforts by bad actors to use its AI models for malicious activity such as cyberattacks, surveillance, and research that could have led to biological weapons, ranging from phishing and credential theft to exploiting vulnerable systems and stealing large volumes of data.
These revelations have been made in a new report by Anthropic on the misuse of its AI models, including Claude, including state actors running intelligence operations and developing weapon system. The actors included suspected state-sponsored groups, financially motivated criminals and politically motivated individuals.
The report, named “Detecting and countering misuse of AI: September 2026”, details cyber operations identified and disrupted by Anthropic between December 2025 and August 2026, in which threat actors used the Claude AI models. The actors included suspected state-sponsored groups, financially motivated criminals and politically motivated individuals. This is Anthropic’s fourth report and goes on to show how the malicious use of Claude has evolved over time.
One of the cases detailed in the report involved a Russian state-nexus espionage actor, identified by Anthropic as GTG-20006, which used AI-driven workflows to automate operations from infrastructure development and phishing to maintaining access to compromised systems and stealing data.
The group used a toolkit that included Windows-based implants, a mobile exploitation kit, a credential-stealing tool targeting passwords stored in browsers, and a phishing platform designed to imitate government organisations.
Anthropic’s report said AI’s role in cyber operations is becoming increasingly autonomous, with Claude being used not only as an assistant but also to execute or coordinate parts of attacks.
In several cases, multi-agent AI systems carried out reconnaissance, exploitation and data exfiltration, while humans largely remained involved in selecting targets and reviewing stolen information. The report said the actor also used AI to drive its phishing operations.
“They developed AI-driven workflows to research, then register domains, and then configure the hosting infrastructure used to send phishing emails,” Anthropic said.
The workflows were also used to send phishing emails and monitor command-and-control channels for successful compromises. Anthropic identified more than 20 organisations targeted in the group’s planning, reconnaissance and live operations.
These included government ministries, defence and intelligence bodies, embassies, diplomatic missions, think tanks and defence-industrial companies. The report also highlighted financially motivated attacks in which Claude was used to facilitate large-scale data theft and supply chain compromises.















