Anthropic's September 2026 threat intelligence report details espionage, extortion, and drone-SDK theft via Claude
Anthropic published its latest threat intelligence report on September 10, 2026, detailing eight months of misuse cases its Threat Intelligence team detected and disrupted on Claude, including state-linked espionage operations and a large-scale data extortion campaign.
What's new
The report states that "over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity," covering activity between December 2025 and August 2026. Anthropic organizes the findings around "seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation."
Three case studies stand out:
- GTG-20006 (Russian espionage): The actor targeted "military intelligence targets in Ukrainian and European governments," and "scanned email services and remote access systems across more than two dozen Ukrainian government organizations." In one operation, the group stole "a complete proprietary software development kit for a drone vision system."
- GTG-50014 (ShinyHunters): This extortion group "exfiltrated more than a terabyte of data, including hundreds of thousands of national identifiers and millions of payment card records." One breach "took only hours from first access to bulk data theft."
- GTG-10007 (Chinese espionage): The operation targeted "roughly fifty organizations" and "produced multiple previously-unknown vulnerabilities."
Anthropic also notes that none of the disrupted misuse involved "Claude Fable or Mythos-class models, with the exception of one illicit distillation case" — meaning its newest model family was almost entirely absent from the abuse it found.
Context
This is the latest in a series of periodic threat intelligence disclosures Anthropic has published since 2025, each surfacing specific, named threat clusters (tracked under "GTG" codenames) rather than aggregate statistics alone. Earlier reports in the series have covered state-sponsored cyber-espionage campaigns and AI-assisted malware development; this edition extends the case-study format to extortion and large-scale credential/data theft operations, and is the first to name a dedicated "conventional weapons development" harm category in its taxonomy.
Why it matters
The report is a rare, quantified look at how state and criminal actors are actually trying to weaponize a frontier AI assistant, rather than a hypothetical about future misuse. The drone-vision-system SDK theft and the multi-terabyte extortion haul both show that the misuse isn't limited to chat-based social engineering — actors used Claude inside real intrusion and exfiltration workflows against government and corporate targets. That Anthropic can name specific threat-group codenames, timeframes, and stolen data volumes also signals a maturing detection and attribution capability sitting behind the API, which is itself a competitive and policy-relevant claim as regulators scrutinize how frontier labs monitor for abuse.
Corroborating sources
- Reuters
https://www.reuters.com/world/china/how-anthropic-says-claude-was-used-weapons-spying-cyber-operations-2026-09-11/
- Anthropic
https://www.anthropic.com/threat-intelligence-report-september-2026
“Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity.”
- Theguardian
https://www.theguardian.com/world/2026/sep/12/ukraine-war-briefing-russian-developers-used-ai-to-build-kamikaze-attack-drone-software-anthropic-says