Claude Is Being Weaponized by State Hackers and Lone Operators Alike, Anthropic Warns
Artificial intelligence has fundamentally changed the economics of cybercrime, allowing individual hackers to orchestrate breaches that would have required teams of skilled operators just a year ago. According to Anthropic's latest threat intelligence report published on September 10, 2026, Claude models are being actively misused by state-sponsored groups, criminal syndicates, and commercial spyware vendors to conduct large-scale cyberattacks at machine speed.
The report, which covers Claude misuse disrupted between December 2025 and August 2026, documents a troubling shift in how attackers operate. Rather than relying on novel hacking techniques, threat actors are using Claude Haiku, Sonnet, and Opus models to automate the grunt work of reconnaissance, tool development, and post-exploitation activities. The result is breaches completed in two to three hours, with individual operators managing dozens of victims in parallel.
How Are Attackers Using Claude to Breach Organizations?
- Autonomous Reconnaissance: AI agents perform network scanning and vulnerability discovery at machine speed, with one Chinese-speaking group generating more than a dozen potential zero-day findings in a single month against approximately 50 organizations.
- Rapid Credential Exploitation: Affiliates of the ShinyHunters extortion collective escalated from a single stolen developer token to full administrative control of a victim's cloud environment in roughly three hours, while another campaign dumped over 2,100 Azure Active Directory token sets from more than 40 corporate tenants in about 34 hours.
- Adaptive Malware Modification: When security products flag attackers' implants, Claude is used to modify and redeploy them in a continuous loop, inverting the cost burden back onto defenders who must constantly adapt their detection methods.
- Supply Chain Infiltration: A Russian-speaking financially motivated actor planted malicious instructions in an AI vendor's automated evaluation sandbox, which handed over production application programming interface (API) keys for several model providers, enabling follow-on campaigns against roughly 30 AI companies in about four days.
Which Threat Groups Are Exploiting Claude?
Anthropic identified multiple categories of attackers leveraging Claude's capabilities. GTG-20006, attributed to the Russian espionage group Midnight Blizzard, targeted Ukrainian government, military, and diplomatic staff. The group bulk-exported mailboxes from at least two drone component makers, stole a proprietary software development kit for a drone vision system, and compromised hotel guest Wi-Fi vendors to reach travelers.
GTG-10007, a Chinese-speaking group likely based in Changsha, ran what Anthropic calls automated exploit foundries against approximately 50 organizations. Notably, two of the operators were identified as undergraduate students, demonstrating how AI is lowering the barrier to entry for sophisticated cyberattacks.
Beyond state-sponsored actors, Anthropic documented how commercial spyware vendors and financially motivated criminals are adopting the same autonomous operating model. The autonomous approach first documented in a suspected Chinese state-sponsored campaign last November has since spread to every class of actor investigated in the report.
What Is the Distillation Campaign Against Claude?
Perhaps most concerning, Anthropic accuses seven Chinese AI labs of illicitly distilling Claude's capabilities to train their own models. Alibaba Group Holding Ltd. ran what Anthropic describes as "the largest distillation attack we have ever measured," using a fixed prompt to force Claude Opus 4.6 and 4.7 to write out their chain-of-thought reasoning. Those transcripts were then used to train Qwen 3.5, 3.6, and 3.7 models.
The scale of the Alibaba campaign was staggering. It peaked at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts, with more than 151 million total exchanges counted between May and July 2026.
Moonshot AI and DeepSeek Ltd. are accused of quietly forwarding their own customers' requests to Claude and saving the answers for training. In one 10-day stretch, Moonshot relayed almost 300,000 requests from users who believed they were interacting with Kimi, Moonshot's own AI assistant. Sensitive data came along with those requests, including footage from hundreds of surveillance cameras in Chengdu uploaded by a user Anthropic assessed as likely affiliated with China's People's Liberation Army.
The other four labs named in the report are Xiaomi Corp., Zhipu, SenseTime Group Inc., and MiniMax. Anthropic said MiniMax set up a proxy service through an undisclosed shell company that sells access only to Anthropic and OpenAI Group PBC models. This represents the first time Anthropic has accused Chinese labs of distillation since February 2026.
What Other Misuses Has Anthropic Documented?
Beyond cyberattacks and model distillation, Anthropic disrupted several other concerning applications of Claude. Lakana 360, a surveillance platform built with Claude for Mali's state intelligence service, monitors roughly 25 million SIM cards across all three of the country's mobile operators and was designed to circumvent legal requirements for court orders.
Anthropic also disrupted six weapons development cases in China, Russia, and Yemen, including an effort by likely freelance Russia-based developers to build an autonomous kamikaze drone swarm using Claude.
How Is Anthropic Responding to These Threats?
Anthropic has taken several defensive measures in response to the documented misuse. The company banned the accounts involved in these campaigns and shared intelligence with authorities and industry partners where appropriate. Additionally, Claude now summarizes its internal reasoning before responding to users, making stolen transcripts less useful for training competing models.
The company has also implemented geographic restrictions. Accounts operating from unsupported countries such as China, Russia, and Iran can now be required to verify their identity or lose access to Claude services.
The threat landscape Anthropic describes underscores a fundamental challenge in the AI era: as models become more capable, they simultaneously become more powerful tools for malicious actors. The democratization of AI capabilities means that sophisticated cyberattacks once requiring state-level resources and teams of specialists can now be executed by individuals or small groups working at machine speed, fundamentally reshaping the cybersecurity landscape.