Anthropic's Threat Report Finds AI Moving From Assistant to Orchestrator

September 11, 2026
Anthropic disrupted malicious uses of Claude spanning cyber operations, surveillance, fraud, weapons research and other threats between December 2025 and August 2026.
Anthropic's Threat Report Finds AI Moving From Assistant to Orchestrator

In a threat intelligence report, Anthropic details malicious uses of Claude that it disrupted between December 2025 and August 2026 across seven areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation. Haiku, Sonnet and Opus models were used in the documented cases.

Most of the operations were enabled by AI through direct execution or orchestration rather than question and answer assistance. Attackers used multi agent frameworks for reconnaissance, exploitation and data exfiltration, with humans remaining in the loop to set targets and review what was taken.

The case Anthropic uses to illustrate the shift is GTG-20006, which it says increased its speed by automating its operations. Anthropic puts its own attribution carefully: it says its attribution is consistent with public reporting linking the actor to Midnight Blizzard, and that one operator is a Russian speaker whose tradecraft and targeting are consistent with Russian state nexus espionage. The operations attacked military intelligence targets in Ukrainian and European governments, diplomatic and defence organisations, and individuals connected to US foreign policy.

The detail that matters for defenders is what the automation replaced. Static detection has historically imposed cost on attackers, who had to rebuild toolkits once signatures caught them. This actor ran an AI assisted workflow that watched whether security products detected its malware and rebuilt and redeployed the toolkit when they did, which removes the delay that made detection expensive for the attacker.

Anthropic says it disrupted the activity in each case, used what it learned to strengthen safeguards, and shared intelligence with authorities and industry partners where appropriate.

We hope you enjoyed this article.

Subscribe to Cybersecurity AI Weekly

Weekly newsletter about AI in Cybersecurity.

Industry analysis

2025 Global Business Services Agenda: Gen AI Takes Center Stage

The Hackett Group

This industry analysis by The Hackett Group explores the transformative impact of generative artificial intelligence (Gen AI) on global business services (GBS) in 2025. The study highlights the shift from exploration to acceleration of Gen AI initiatives, with 89% of executives advancing these projects to improve customer satisfaction, innovate products, and reduce costs. The report also discusses the challenges and strategies for successful Gen AI adoption, emphasizing the need for a technology-enabled operating model and the importance of reskilling the workforce.

Read more