News12 days ago

Anthropic Published What Nation-State Hackers Actually Did With Claude and the Numbers Are Specific

Anthropic's September 2026 threat report names four cyber operations groups and five influence campaigns that used Claude for espionage, data theft, election manipulation, and autonomous vulnerability research. One group stole 300,000 identity records. Another exfiltrated over a terabyte. The report is 20 pages of specifics, not a vague warning.

The WJS Desk

Sep 12, 2026 · updated 12 days ago · 5 min read

Photo by Tima Miroshnichenko on Pexels

On September 11, Anthropic published its most detailed threat intelligence report to date, covering nine distinct groups that used Claude models for cyber operations and influence campaigns between December 2025 and August 2026. This is not a hypothetical risk assessment. It names operational groups by tracking codes, documents specific techniques, and reports data volumes down to the terabyte. We read the full report, and the specifics matter more than the headline.

The most important technical detail: all documented misuse involved Claude Haiku, Sonnet, and Opus. None of the cases involved Fable or Mythos-class models, with one exception related to illicit distillation. Anthropic states that Mythos includes safeguards that "greatly reduce its ability to perform harmful cyber tasks."

The cyber operations

Four major groups are documented. We are summarising from Anthropic's report and attributing every claim to them.

GTG-20006 (Russian espionage, linked to Midnight Blizzard): Used Claude for reconnaissance, phishing infrastructure, and autonomous malware modification. Anthropic reports this group targeted more than 20 organisations including Ukrainian government, military, and drone manufacturers. The specific numbers: 300,000 national identity records stolen from a North African target, 500,000 company registry entries exfiltrated, and mailboxes from at least 8 government organisations accessed. The group used Claude to automatically rebuild malware when security products detected it.

GTG-10007 (Chinese-speaking espionage): Conducted autonomous vulnerability research against security products and, according to Anthropic, identified multiple zero-day vulnerabilities that were validated in lab environments. This group operated against roughly 50 organisations globally and ran what the report calls "agent swarms" for reconnaissance and post-exploitation, maintaining persistent campaign memory across sessions.

GTG-50014 (ShinyHunters, financially motivated): Downloaded 1.8 million Android APKs to search for hardcoded secrets. Anthropic reports they exfiltrated over 1 terabyte of data from a technology provider, accessed tens of millions of passenger records from an airline, and escalated from a single developer token to full administrative control in approximately 3 hours.

GTG-50029 (French-speaking hacktivist): A single operator who built custom Rust-based scanning infrastructure, compromised at least 14 of 42 tracked targets, exfiltrated 12 to 26 GB of data including political donor records, and built a doxxing platform with tens of millions of records. Anthropic describes this as one person developing a complete multi-function attack infrastructure using Claude.

What the report does not say: It does not claim Claude was the only tool these groups used, or that Claude's capabilities were necessary for the attacks. These are sophisticated groups with existing toolchains. Claude was one tool among many, and the report does not attempt to quantify how much faster or more effective it made them.

The influence operations

Five influence campaigns are documented, and the scale varies dramatically.

The largest by volume was GTG-54002, described as a commercial "influence-as-a-service" operation. Anthropic reports it mass-produced political content across approximately 70 fabricated news websites, operated over 70 linked inauthentic X accounts and 250 commenting accounts, and published 8,913 articles in roughly 20 languages across six continents. The technique: taking legitimate journalist articles and rewriting them with a political slant for different audiences.

GTG-84005, identified as BBS Bilisim Teknolojileri, is documented as managing approximately 1,000 fake X accounts for Malaysian election manipulation. Anthropic reports they used real census and voter records for micro-targeting along racial and religious lines, generated millions of artificial engagements for government officials, and operated a synthetic news outlet called "Malaysia Pulse." The report quotes the firm's own marketing: "military-grade, AI-driven, real-time political operations ecosystem."

GTG-04001, a Russian state-aligned operation in the Central African Republic, used Claude as what Anthropic calls the "production backbone" for propaganda across Radio Lengo Songo (98.9 FM), coordinated with RT, Sputnik, and TASS. This included forged government documents. Anthropic rates this as "Category Four" on the Breakout Scale, meaning measurable real-world impact.

What Claude refused to do

The report includes examples where Claude's safety training worked. According to Anthropic, Claude refused to name specific individuals as militants when asked, refused to generate explicit defamation on demand, and refused certain high-risk requests that would have directly enabled physical harm. These are Anthropic's claims about their own system, and we cannot independently verify them, but the fact that they are specific enough to describe (rather than generic "our safety measures worked") is worth noting.

  1. AI democratised sophistication. The capability gap between state-sponsored and non-state actors narrowed. A solo French-speaking hacktivist built infrastructure that would previously have required a team.
  2. Autonomous operations escalated. Multi-agent frameworks ran with minimal human oversight. The Chinese-speaking group's "agent swarms" are the clearest example.
  3. The AI supply chain became a target. GTG-50020, a Russian financial crime group, compromised an AI vendor evaluation sandbox to steal production API keys, attacking approximately 30 AI companies within 4 days. They specifically pursued pre-release Claude model access, unsuccessfully.
  4. Techniques diffused across threat classes. State-sponsored, criminal, hacktivist, and commercial groups all adopted identical techniques independently.
  5. Speed compressed. Operations that previously took weeks completed in hours or days. ShinyHunters went from a single developer token to full admin access in 3 hours.

What Anthropic did about it

According to the report, all identified accounts were banned, intelligence was shared with authorities and industry partners, new detection methods targeting behavioural signatures were deployed, and technical indicators (domains, IPs, identifiers) were published for the industry. The monitoring approach focuses on multi-agent framework usage patterns, agentic coding signatures, persistent memory files, and coordinated inauthentic behaviour.

Why this report is different

AI safety discussion has been dominated by hypotheticals for two years. Anthropic's own previous public communications leaned toward theoretical risk (a researcher quitting over existential concerns made headlines last week). This report is different because it replaces theory with incident data. Specific groups, specific techniques, specific volumes, specific timelines.

The uncomfortable reading is that every scenario AI safety researchers warned about, from autonomous vulnerability research to election manipulation to weaponised influence-as-a-service, has already happened. Not in a red team exercise. In the field, against real targets, for real stakes.

The debate about whether AI would be used for cyberattacks is over. The question now is whether detection and response can keep pace with operations that compress weeks into hours.

We think this report should be required reading for anyone building AI products, not because it tells you what to do, but because it shows you exactly what the threat model looks like when the hypotheticals stop being hypothetical.

Share

Anthropic names 9 groups that used Claude for espionage, zero-day hunting, and election manipulation. 300K records stolen. 1,000 fake accounts. The report, not the theory. #Cybersecurity #AI #Anthropic #ThreatIntelligence

Never miss a ship

The best stuff that shipped this week, delivered every Thursday. Free, no spam. We read all the boring stuff so you get the fun parts.

Keep reading