Anthropic says AI has moved from assisting cyberattacks to orchestrating them

Anthropic published its third threat intelligence report on Friday, detailing how malicious actors attempted to weaponize its Claude models between December 2025 and August 2026 — and how the company disrupted those efforts across seven categories of harm.
The most significant escalation documented in the report is a shift in how AI is being used in cyberattacks. Where previous cases involved AI assisting human attackers, an operation Anthropic tracks as GTG-20006 — with tradecraft consistent with Russian state-linked group Midnight Blizzard — deployed customized AI-driven workflows across the full attack chain: target research, phishing infrastructure setup, exploitation, credential harvesting, lateral network movement, and data exfiltration. In a separate case, AI agents monitored security product detections of their own malware and automatically rebuilt the code to evade detection — a level of autonomy Anthropic describes as a new threshold.
Bioweapons attempts blocked
Anthropic said it blocked five attempts to use Claude for potential bioweapons research. The cases involved queries about chikungunya, avian influenza, and smallpox. One request asked Claude to help draft a grant application for gain-of-function research aimed at increasing chikungunya's transmissibility and immune evasion capabilities. The company is careful to note that these cases demonstrate AI capability but do not prove intent or that users would have succeeded in developing weapons.
In response, Anthropic has restricted access to its most capable biology-focused models to vetted organizations and said it has shared relevant intelligence with government authorities and industry partners.
Seven Chinese labs attempted illicit distillation
The report also documents illicit model distillation — attempts by outside actors to extract and replicate Claude's capabilities without authorization. Anthropic identified seven China-based AI labs involved. Claude Haiku, Sonnet, and Opus models were used across most misuse cases; one distillation case involved a Fable or Mythos-class model.
Beyond cyber and bioweapons, the report covers influence operations, surveillance systems built to monitor dissidents, scams using fake dating apps, and conventional weapons research. The threat actors span suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals.
The broader warning
Anthropic's central concern in the report is capability democratization: as AI models become more powerful, mounting sophisticated attacks will no longer require advanced technical skills. The company warns that lone individuals could now attempt threats that previously required well-resourced teams.
This is Anthropic's third threat intelligence report since March 2025. The company says it publishes these findings to help other AI developers recognize abuse patterns on their own platforms and to give governments and civil society a clearer picture of how AI-enabled threats are evolving.
Source: Anthropic threat intelligence report, September 2026
Originally reported by Anthropic. Read the original article for additional details.
View original source