A disclosure about observed misuse, not a crime-rate survey
Anthropic has published a threat-intelligence report describing operations that it says tried to use Claude for malicious activity. The report covers activity the company says it identified and disrupted between December 2025 and August 2026. It groups the cases into seven areas: cyber operations, surveillance, influence operations, scams and fraud, biological misuse, conventional-weapons development and illicit model distillation.
This is valuable material, but the scope needs to stay clear. Anthropic says the cases are examples of the most notable and novel activity it found. They are not a random sample of all Claude use, all attempted misuse or all cybercrime. The report is the company's own investigation, published alongside indicators for defenders, rather than an independently audited count.
The most useful reading is therefore narrow. The report shows ways determined people may try to place an AI system inside harmful workflows. It cannot tell us, by itself, how common those workflows are or how much harm they caused compared with attacks that did not use AI.
The key change is a workflow with tools
Anthropic says a majority of the cyber operations it describes used AI for direct execution or orchestration, not merely for isolated chatbot questions. Its examples involve tool-using workflows for reconnaissance, scripting, data processing and adapting a campaign when a step fails. That can reduce the time and specialist knowledge needed to move from one stage of an attack to another.
That does not mean a model picked a target, developed a motive or operated without human direction. In Anthropic's own description, people remained in the loop by choosing targets and reviewing exfiltrated material. The report also describes attackers using stolen credentials, exposed tokens, phishing and other familiar routes to obtain initial access.
The distinction is important. Calling every tool-using workflow autonomous can make the problem sound either inevitable or unknowable. A better question is more practical: which steps are being sped up, what access did the operator already have, and where can a defender still break the chain?
Old security failures are still the doorway
The report's cyber cases do not turn basic security into a relic. On the contrary, the company repeatedly describes familiar weaknesses: compromised credentials, exposed keys, phishing, weakly protected cloud services and software flaws. AI may help an operator interpret a strange environment or automate repeated work after access is gained. It does not make an exposed secret harmless.
That is a more grounded way to think about the risk. A company cannot solve it only by asking whether employees are allowed to use one model. It also needs to know where credentials live, who can use them, what a connected agent can reach, how unusual actions are logged and who can stop a workflow quickly.
None of those controls guarantees that an incident will not happen. They can make an attack harder to start, easier to detect and less useful when it is discovered. That remains true whether the attacker uses a spreadsheet, a conventional script or a model-assisted workflow.
Why transparency from a provider helps, and where it stops
Anthropic says it disrupted the activity, strengthened safeguards and shared intelligence with authorities and industry partners where appropriate. It has also made a set of indicators available for defenders. Publishing case material can help other security teams look for patterns they might otherwise miss.
But a provider has unavoidable blind spots. It can see activity on its own service and investigate accounts linked to that activity. It cannot see every model, every stolen key, every local tool or every operation that happens elsewhere. It also makes judgment calls about attribution, significance and what details to release.
That is why provider reports should be read as one evidence source among several, not as a self-contained picture of the threat. Independent research, incident reporting, law-enforcement work and disclosures from affected organisations are still needed to test the broader claims.
What is confirmed, what Anthropic says, and what remains open
Confirmed: Anthropic published its September 2026 threat-intelligence report and says it covers activity disrupted from December 2025 through August 2026. The report names seven harm areas, says Haiku, Sonnet and Opus appeared in the described cases, and provides public indicators associated with some cyber activity.
Anthropic's claims: the cases show AI increasing the speed, scale and depth of harmful operations; many cyber cases used multi-agent or tool-using workflows; and the company disrupted the activity and improved safeguards. Those findings are evidence from Anthropic's investigation, not independently verified results across the wider threat landscape.
Open questions: how representative the selected cases are, how often comparable workflows succeed on other systems, the full rate of false negatives and false positives in provider monitoring, what independent investigators will confirm, and which defensive measures make the largest difference in practice. The report raises the stakes for ordinary security discipline. It does not show that human accountability has disappeared.
Sources
- Anthropic — Detecting and countering misuse of AI: September 2026Primary Anthropic threat-intelligence report, published 10 September 2026. Source for the stated reporting period, seven harm areas, model families, selected case descriptions, provider assessment and disclosure of indicators.
- CISA — Secure by DesignOfficial US cybersecurity guidance used only for general context that resilient systems reduce preventable attack paths. It does not verify Anthropic's specific cases or attribution.
- NIST — Artificial Intelligence Risk Management FrameworkAuthoritative framework used for general context on managing AI risks as part of a wider organisational risk process, not as evidence for the individual cases in Anthropic's report.



