Editorial illustration: on a dim concert-hall stage, a single tiny conductor faces an orchestra formation made entirely of autonomous machine terminals executing looping tasks; in the shadows at the back, one large chair sits under a dust cover, unused — the flagship model no attacker bothered with.
The autonomous-attack playbook first documented last November has spread to every class of actor. Attackers use the cheap older models, not the flagship., AI-generated illustration, not a news photograph

Anthropic on September 10 published its roughly 36,000-word Threat Intelligence Report for September 2026 — the fourth in a series that began in March, August and November 2025 — disclosing misuse its team identified and disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and illicit distillation.

The report's core finding is a shift in roles: the autonomous agent-driven attack model first documented in November 2025 has now proliferated across every class of actor Anthropic investigated. In the report's own words, AI has "collapsed the labor and tooling gap" that once separated state-sponsored operations from individual operators — and for threat-intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation.

All of the documented misuse ran on Claude Haiku, Sonnet and Opus; with the exception of one illicit distillation case, none touched the newest Fable or Mythos-class models. Attackers rode the cheap old horses, not the flagship.

[1][2]

The weight of several cases

  • GTG-20006: Attribution is consistent with public reporting on Midnight Blizzard; one operator uses the handle "JackPoterz." The actor hit more than 20 organizations concentrated in Ukrainian government, military and diplomatic bodies; compromised at least three hotel WiFi vendors to hijack DNS records; took over the WhatsApp accounts of at least two former senior Ukrainian officials; and stole more than 300,000 national identity records plus commercial registry data covering over half a million companies from a North African government technology authority. Its AI agents autonomously rebuilt the operation's malware whenever security products detected it.
  • GTG-50014: Suspected ShinyHunters affiliates mass-downloaded 1.8 million Android APKs and scanned them for hardcoded secrets; one breach exfiltrated more than a terabyte including millions of payment card records; another affiliate pulled data from roughly 200 downstream customers of a breached SaaS provider and dumped more than 2,100 Azure AD token sets spanning over 40 corporate tenants in about 34 hours — with AI agents performing nearly all of the work, per the report.
  • GTG-50020: A Russian-speaking financially motivated actor exfiltrated roughly 26GB and demanded $1.5–2.5 million, then attacked about 30 AI companies in roughly four days with the stated goal of reaching a pre-release Claude model. The way in: injecting malicious instructions into an AI vendor's evaluation sandbox and walking out with production API keys. Anthropic says every path failed and its own systems were never compromised.
  • GTG-10007: Chinese-speaking operators, likely based in Changsha, Hunan, two of them identified as undergraduate students, targeted roughly 50 organizations and ran an autonomous vulnerability research program; one workflow iterating on network appliances yielded more than a dozen possible zero-day findings in a single month.

The report also documents: an intelligence contractor in Mali using Claude as the primary engineering workforce for a surveillance platform covering roughly 25 million SIM cards; a fake dating-app network running more than 4,700 AI personas talking to at least 25,000 real people; and a Yemen-based cell using Claude Code to develop ballistic missile guidance software. Stolen API keys are now loot in their own right: fake "discounted Claude" resellers shipped credential harvesters disguised as Claude Code installers, and several actors used prompt injection against LiteLLM wrapper services to steal production keys.

[1][2]

The biological case and a self-disclosed gap

The most closely watched case came in May: a researcher asked Claude to help draft a grant application for work that would engineer chikungunya — a mosquito-borne virus causing prolonged, severe joint pain — to become more harmful and capable of repeatedly infecting live animals. What triggered the block was that the work was intended for a military research institute. Anthropic concedes it cannot definitively determine whether blocked research is legitimate dual-use science or weapons development, and says it errs toward blocking.

The report also discloses a defender-side failure: from May 2025 to April 2026, biological-risk filters were disabled on contractor traffic — roughly 133 million exchanges involving about 50,000 contractors. A retrospective review flagged 1,197 high-risk transcripts; Anthropic says it found no confirmed evidence of actual bioweapons uplift from the gap. The tension inside the report is that the defense system's biggest hole was not a clever model but a switch left off.

[1][2]

Distillation: a public naming

For the first time, the report names names: since February 2026, Anthropic says it has disrupted distillation campaigns from seven China-based labs. Alibaba's extraction effort is described as "the largest distillation attack we have ever measured" — more than 151 million exchanges between May and July 2026. Moonshot and DeepSeek allegedly went further, silently relaying their own users' prompts to Claude and saving the exchanges for training. Anthropic's countermeasures include proxy-network attribution, updated extraction classifiers, mandatory identity verification for suspicious accounts, and "preserved thinking" in Fable 5.1 to prevent manipulation of reasoning traces.

[1][2]

How to read this report

This is Anthropic's fourth report of its kind, and the self-disclosure posture has itself become part of industry convention. Two caveats belong next to the headline. First, every case in the report is a disrupted case — the sample is inherently biased toward defensive success. Second, the actors all used older-generation models — which can be read either as proof that the newest safeguards work, or as proof that attackers do not need anything stronger. Anthropic's own evaluations concede that current models can complete dangerous biological tasks that older ones could not. The barrier is coming down; this report documents the part of that process visible above the waterline.

[1]