...
...
Next Story

Phishing, weapons and spying: Top 5 misuses of AI flagged by Anthropic

These revelations have been made in a new report by Anthropic on the misuse of its AI models, including Claude.

Updated on: Sep 11, 2026, 13:49:55 IST
Advertisement

Hackers, cybercriminals, and suspected state-linked groups are increasingly using artificial intelligence (AI) to automate cyberattacks, ranging from phishing and credential theft to exploiting vulnerable systems and stealing large volumes of data.

The report, named “Detecting and countering misuse of AI: September 2026”, details cyber operations identified and disrupted by Anthropic between December 2025 and August 2026, in which threat actors used the Claude AI models. (AP Photo/Patrick Sison)
The report, named “Detecting and countering misuse of AI: September 2026”, details cyber operations identified and disrupted by Anthropic between December 2025 and August 2026, in which threat actors used the Claude AI models. (AP Photo/Patrick Sison)

These revelations have been made in a new report by Anthropic on the misuse of its AI models, including Claude. The report, named “Detecting and countering misuse of AI: September 2026”, details cyber operations identified and disrupted by Anthropic between December 2025 and August 2026, in which threat actors used the Claude AI models.

The actors included suspected state-sponsored groups, financially motivated criminals and politically motivated individuals.

Top 5 findings in the Anthropic report

Claude AI being used to coordinate attacks: Anthropic said AI's role in cyber operations is becoming increasingly autonomous, with Claude being used not only as an assistant but also to execute or coordinate parts of attacks.

In several cases, multi-agent AI systems carried out reconnaissance, exploitation and data exfiltration, while humans largely remained involved in selecting targets and reviewing stolen information.

The group used a toolkit that included Windows-based implants, a mobile exploitation kit, a credential-stealing tool targeting passwords stored in browsers, and a phishing platform designed to imitate government organisations.

Weapon building and espionage: Anthropic has said that it caught China using Claude to help develop an anti-torpedo weapons system intended for the People’s Liberation Army Navy.

The company also said that it shut down multiple cases of state-sponsored surveillance operations that used its AI models, and warned that governments and state-aligned actors are increasingly using AI to spy on ethnic minorities and dissidents.

“We identified a China-based threat actor who used Claude to advance three parallel tracks of work on an anti-torpedo weapons system,” Anthropic said.

AI phishing operations: The report said the actor also used AI to drive its phishing operations.

“They developed AI-driven workflows to research, then register domains, and then configure the hosting infrastructure used to send phishing emails,” Anthropic said.

The workflows were also used to send phishing emails and monitor command-and-control channels for successful compromises. Anthropic identified more than 20 organisations targeted in the group's planning, reconnaissance and live operations.

These included government ministries, defence and intelligence bodies, embassies, diplomatic missions, think tanks and defence-industrial companies.

Supply chain compromise: The report also highlighted financially motivated attacks in which Claude was used to facilitate large-scale data theft and supply chain compromises.

In one attack on a software-as-a-service (SaaS) provider, hackers extracted data belonging to around 200 downstream customer organisations and obtained more than 2,100 Azure AD token sets spanning over 40 corporate tenants in about 34 hours. Anthropic said AI agents performed nearly all of the work.

In another SaaS compromise, an attacker exploited a cross-site scripting vulnerability, escalated privileges and eventually exfiltrated data from thousands of downstream customer organisations.

Claude was used to help understand developer and authentication APIs, create privileged tokens and build tools for bulk data exports and cross-tenant data collection.

AI allowing faster attacks on more targets: Anthropic said the findings show that AI is allowing attackers to operate faster and across more targets with fewer resources, while increasingly taking over tasks that previously required skilled human operators.

It said, “While this is a danger, the risk from AI adoption is more pronounced across the cyber kill chain, where adversaries can operate faster, across a broader and deeper surface area, with fewer resources”.

Steps taken by Anthropic to intervene

Anthropic said it has taken steps to disrupt such malicious activity by banning accounts linked to threat actors and strengthening its systems to identify similar attacks in the future.

In one cyber operation, the company said it “banned accounts associated with the actors and deployed additional monitoring to detect and ban related activity.”

The company also said it uses findings from its investigations to improve safeguards against future misuse.

In another section, Anthropic said, “We banned the accounts associated with these operations and are mapping their wider footprints,” adding that it was tracking the actors’ digital signatures to prevent future misuse and incorporating the findings into new safeguards and model training.

 
ABOUT THE AUTHOR
Shivam Pratap Singh

Shivam Pratap Singh is a digital journalist who works as a Deputy Chief Content Producer with Hindustan Times. Having previously worked with various platforms covering national, international as well as sports events, he blends in various topics to easy to read news pieces for the benefit of the reader. Shivam holds a Master's degree in International Relations from Jamia Millia Islamia, bringing in a unique perspective for whatever is happening around the world. An avid reader, he can be seen immersed in books and book shops while not working. Shivam treats every topic almost equally but loves to right about foreign affairs and politics of India. He has over half-a-decade of experience in digital journalism though his career started in print.

Get the latest World News, breaking headlines and global updates from the US, UK, Pakistan, Bangladesh, Russia and other countries. Follow major international events on Hindustan Times.
Get the latest World News, breaking headlines and global updates from the US, UK, Pakistan, Bangladesh, Russia and other countries. Follow major international events on Hindustan Times.
SHARE THIS ARTICLE ON
Notifications

Get breaking alerts directly from the newsroom

Notifications are on!You'll be notified when news breaks