Agents
Anthropic threat report: in most cases, AI executed or orchestrated the operation
Anthropic's latest threat intelligence report, published Sept. 10, describes misuse of its Claude models that it disrupted between December 2025 and August 2026. The company said a majority of the operations it describes relied on AI to execute or orchestrate the work, not only to advise a human operator.
The report spans seven areas: cyber operations, surveillance, influence campaigns, conventional weapons development, biological misuse, scams and fraud, and illicit model distillation. Anthropic said the cases are its most notable and novel examples, not typical misuse, and that the operators behind the cyber cases ranged from state services to lone individuals.
In the cyber section, the company describes multi-agent frameworks carrying out reconnaissance, exploitation and data theft, with people still choosing the targets and reviewing what was taken. One espionage group, tracked as GTG-10007 and attributed to Chinese-speaking operators that included two undergraduate students, ran what the report calls agent swarms: a lead agent split up the work and handed pieces to subagents running in parallel. In a separate case filed under the ShinyHunters name, one stolen developer token gave attackers complete administrative control over a victim's cloud account in about three hours.
Anthropic said the activity used its Haiku, Sonnet and Opus models, and that none of the cases involved its Fable or Mythos-class models apart from one distillation case. It said it disrupted each operation, tightened safeguards and shared intelligence with authorities and industry partners, and it released indicators of compromise alongside the report. The company noted that its visibility ends once an operation leaves its platform and that some figures taken from the actors' own dashboards could not be verified.
Source details
- Source
- Anthropic
Source reporting
Read the original reporting and research behind this briefing.