On September 10, 2026, Anthropic released its latest threat intelligence report detailing misuse of its Claude models disrupted between December 2025 and August 2026. The report covers seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation.
Anthropic's Threat Intelligence team identified and disrupted operations involving suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals. The cases are described as the most notable and novel threat activity identified to date, not typical misuse.
Claude Haiku, Sonnet, and Opus models were used across the disrupted operations. None of the misuse cases involved Claude Fable or Mythos-class models, with the exception of one illicit distillation case. Anthropic shared intelligence with authorities and industry partners where appropriate.
The September report builds on previous threat intelligence publications from March, August, and November 2025. Earlier in 2026, Anthropic published a June report mapping a year of AI-enabled cyber threats to the MITRE ATT&CK framework and a February report detailing industrial-scale distillation campaigns by DeepSeek, Moonshot, and MiniMax.
Confirmed
- Report publication date: September 10, 2026
- Coverage window: December 2025 through August 2026 (eight months)
- Models involved: Claude Haiku, Sonnet, and Opus
- Models not involved: Claude Fable or Mythos-class models, except for one illicit distillation case
- Seven harm categories documented with case studies
- Intelligence shared with authorities and industry partners where appropriate
- Previous reports published in March, August, and November 2025
- June 2026 report mapped AI-enabled cyber threats to MITRE ATT&CK
- February 2026 report identified distillation campaigns by DeepSeek, Moonshot, and MiniMax
Unknown
- Exact number of disrupted operations or accounts
- Technical details of detection methods and safeguards
- Specific identities of threat actors beyond broad categories
- Whether any disrupted operations caused measurable real-world harm before detection
- Volume of API calls or compute used by threat actors
- Independent verification of the distillation allegations against DeepSeek, Moonshot, and MiniMax
Our take
Anthropic's decision to name specific Chinese AI labs in the distillation section marks a shift from previous reports that described threat actors in generic terms. The allegations — that DeepSeek, Moonshot, and MiniMax relayed user traffic to Claude to harvest training data — are serious but rest on Anthropic's internal telemetry without independent forensic corroboration published alongside the report. For enterprise customers, the more actionable signal is that Haiku, Sonnet, and Opus remain the primary attack surface; Fable and Mythos-class models appear largely insulated from misuse so far.