Chips & compute
What Anthropic's new AI misuse report means for you
Anthropic says attackers are using Claude to run whole hacking and spying operations, not just answer questions.
The answer
Anthropic banned accounts using Claude for hacking, spying and copying rivals' models.
Anthropic has published a report detailing how people misused its Claude chatbot over the past nine months, including cases where attackers used it to help run cyberattacks, track people, and copy its technology.
What happened
On 10 September 2026, Anthropic released its fourth threat intelligence report, covering misuse of Claude that its safety team found and shut down between December 2025 and August 2026, according to Anthropic.
The report's central finding is that attackers are no longer just asking Claude for advice or snippets of code. Instead, they are getting it to act as an orchestrator, handling multiple stages of an operation on its own.
One case, linked to Russia and consistent with a group known as Midnight Blizzard, used Claude to automate reconnaissance, build malware and rewrite that malware whenever security tools detected it, in a repeating loop. This targeted more than 20 organisations, including drone makers and Ukrainian officials.
A separate case, based in China, used Claude to sort through messages from over 100 WhatsApp groups and dozens of Telegram channels, turning casual chatter into structured data used to track Uyghurs in Syria. Anthropic said Claude also helped draft restricted briefings listing dissidents and diaspora communities.
Anthropic also accused seven Chinese AI labs, Alibaba, DeepSeek, Moonshot, Xiaomi, Zhipu, SenseTime and MiniMax, of using thousands of fraudulent accounts to harvest Claude's responses, a technique called distillation, where one company trains its own model by copying another's answers.
Other cases included nine state-linked influence campaigns from countries including Turkey, Iran and Russia, a criminal group called ShinyHunters using Claude to speed up hacking, and two undergraduates in China running an automated system for finding software vulnerabilities, described as an "exploit foundry". Reuters, via US News, reported on the disruptions.
Anthropic said all the accounts involved have been banned. Most cases used older Claude models, Haiku, Sonnet and Opus, rather than its newer Fable or Mythos-class models, with one exception among the distillation cases.
What it means for you
This report is about misuse by other parties, not a change to how you can use Claude day to day. There's no indication in the report of new restrictions, price changes or feature changes for ordinary users.
What it does show is that Anthropic is actively monitoring for large-scale abuse, from state-linked hacking groups to rival AI companies trying to copy its models, and says it is willing to name specific groups and companies publicly when it finds evidence of misuse.
What happens next
Anthropic has not said whether further action, such as legal steps against the named Chinese labs, is planned. The report stands as Anthropic's fourth in a series tracking misuse of its models, suggesting further updates are likely to follow as new cases are found.
Sources
- Countering misuse of AI: September 2026 — Anthropic, 10 September 2026
- Anthropic disrupts Russian, Chinese AI campaigns targeting its Claude models — Reuters via US News, 10 September 2026