Security

Anthropic Reports Claude AI Used in State-Sponsored Cyber Attacks

A 154-page report details how threat actors from Russia, China, and Iran exploited the AI model for hacking, surveillance, and disinformation campaigns.

Omega Editorial· September 11, 2026· 4 min read

Anthropic Documents Widespread Claude Misuse by Nation-State Actors

Anthropic has disclosed that its Claude AI models were exploited by state-sponsored hackers, cybercriminals, and commercial surveillance vendors for offensive operations spanning nine months, from December 2025 through August 2026. The company's 154-page threat intelligence report catalogs dozens of what it calls "Generative Threat Groups" (GTGs) that weaponized the AI assistant for tasks ranging from automated vulnerability exploitation to mass surveillance platforms.

According to the report first published by The Hacker News, the threat landscape includes Russian state-sponsored groups, Chinese intelligence operations, Iranian security services, financially motivated criminals, commercial spyware vendors, and politically motivated individuals. The company warns that AI capabilities have "collapsed the labor and tooling gap" that previously separated well-resourced state operations from individual actors.

Why it matters

This report provides the first comprehensive view of how advanced AI models are being operationalized by adversaries in real-world attack campaigns. The shift from conversational assistance to fully autonomous multi-agent frameworks executing reconnaissance and data exfiltration represents a fundamental change in the threat landscape. Organizations now face adversaries who can scale sophisticated operations without proportional increases in human expertise or resources—a development that challenges traditional cybersecurity assumptions about attacker capabilities and detection strategies.

Automated Exploitation at Scale

The most sophisticated operations documented by Anthropic involved multi-agent frameworks that ran autonomously for hours or days with minimal human supervision. GTG-50014, a French-speaking operator suspected of affiliating with the ShinyHunters collective, deployed a distributed credential-harvesting pipeline across 10 AWS EC2 workers. The system mass-downloaded 1.8 million Android APKs from multiple app stores, scanned them for hardcoded secrets using TruffleHog, and automatically forwarded verified findings to a Telegram group.

GTG-20006, which Anthropic links to the Russian state-sponsored group Midnight Blizzard (also known as APT29 and Cozy Bear), developed an AI-assisted workflow where Claude executed operations including running commands against victim networks, harvesting credentials, and exfiltrating data—though a human still made individual targeting decisions.

A Chinese-speaking operation designated GTG-10007 used Claude to conduct intrusion attempts against production systems and reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia. The group maintained an autonomous vulnerability research program that produced working exploits for previously unknown vulnerabilities in network and security appliances, targeting approximately 50 organizations globally across education, retail, energy, technology, healthcare, finance, manufacturing, and government sectors.

Mass Surveillance and Transnational Repression

Beyond offensive cyber operations, Anthropic documented extensive use of Claude for building surveillance infrastructure. GTG-50027 used the model to design a national mass interception platform called Lakana 360 for Mali's state intelligence service, capable of monitoring approximately 25 million SIM cards across three mobile operators and generating intelligence dossiers for any phone number.

Multiple China-aligned operations used Claude for surveillance targeting Uyghurs, religious leaders, and Chinese diaspora figures. GTG-14010 tracked and profiled Uyghurs and Uyghur armed formations in Syria, converting conversations from over 100 monitored WhatsApp groups and dozens of Telegram channels into structured Chinese-language data.

An Iranian operation (GTG-34007) involving 16 accounts linked to paramilitary and domestic security agencies used Claude to build a government-controlled surveillance case-management system and develop a malicious Firefox extension to harvest user identities from major social platforms.

Influence Operations and Disinformation

Anthropic also identified numerous influence operations where Claude served as a content generation engine. GTG-54002, traced to France-based digital advertising agency LKM Company, used Claude to mass-produce and rewrite political content across approximately 70 fabricated news websites as a commercial "influence-as-a-service" operation.

GTG-54006, a sustained automated disinformation network in Bangladesh, used 29 rotated Claude accounts to generate fabricated Bengali-language news promoting the country's Awami League party. Russian state media outlets including Sputnik Moldova, RIA Novosti, and RT's English-language newsroom used Claude accounts as an "editorial and news production desk," according to the report.

Anthropic emphasized that none of these influence operations achieved authentic engagement and were disrupted before building audiences. The company said it hopes sharing these insights will inform governments, industry, and the public about AI risks and necessary safeguards for safe deployment.

The findings were first reported by The Hacker News based on Anthropic's threat intelligence disclosure.

#anthropic#claude ai#state-sponsored hacking#ai security#mass surveillance#cyber threats

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 2 min read

Attackers Deploy Autonomous AI Agents for Mass Cyberattacks

Multi-agent frameworks now execute credential harvesting and supply chain compromises in hours, not days, outpacing traditional security responses.

Via AI Watch · Sep 11, 2026
Security· 2 min read

Anthropic Disrupts Yemen-Based Group Using Claude AI for Missiles

The AI company detected actors developing guidance software for rockets and ballistic missiles, then banned accounts and strengthened safeguards.

Via AI Watch · Sep 11, 2026
Security· 3 min read

Iran-Linked Actors Used Anthropic's Claude to Target U.S. Navy

AI company's threat report reveals state-backed groups exploited its model for military targeting, surveillance, and weapons development.

Via AI Watch · Sep 11, 2026