• Home
  • AI news
  • Anthropic Warns AI-Powered Cyberattacks and Influence Operations Are Scaling
Anthropic AI threat intelligence report showing AI-powered cyberattacks, surveillance and misinformation

Anthropic Warns AI-Powered Cyberattacks and Influence Operations Are Scaling

Anthropic’s latest threat intelligence report shows that AI-powered cyberattacks are moving from theoretical risks to documented real-world operations.

The company says its Threat Intelligence team identified and disrupted malicious operations that used Claude between December 2025 and August 2026. The activity covered cyberattacks, surveillance, influence operations, scams, biological misuse, weapons development and attempts to steal AI capabilities through illicit model distillation.

What makes the report particularly significant is not simply the number of malicious applications. It is the way attackers are using AI.

In several cases, Claude was not being used as a basic chatbot. It was integrated into larger workflows to write software, process huge amounts of information, generate content, automate research and help operate complex systems.

Anthropic describes this shift as AI moving from an assistant toward an orchestrator of malicious activity.

AI is becoming an operational tool for attackers

Cybercriminals and other threat actors have traditionally needed teams with different skills to conduct sophisticated operations.

They might need programmers to develop tools, analysts to investigate targets, writers to create convincing messages and operators to coordinate the activity.

Anthropic says AI is increasingly allowing some of that work to be combined into automated workflows.

The company identified cyber operations involving suspected state-sponsored groups, financially motivated criminals and politically motivated actors. These operations used Claude across different stages of the cyberattack process.

The important change is therefore not just that AI can generate malicious code.

AI can help attackers move faster, operate at greater scale and cover more of the attack lifecycle with fewer people.

Anthropic says this broader increase in speed, scale and depth may be more significant than the idea of AI simply generating exploits at scale.

8,913 articles: AI-powered influence operations at scale

One of the most striking examples in the report involves an influence operation that used Claude to operate a network of fake news websites and social media accounts.

Anthropic says the network published at least 8,913 articles in roughly 20 languages.

The operation targeted audiences in countries including the United States, Brazil, France and the Democratic Republic of Congo.

Claude was reportedly used for two major tasks.

First, the operators generated original articles for fake news outlets.

Second, they took legitimate journalism and rewrote it into politically slanted versions tailored to specific audiences.

The operation also used fake journalist identities and AI-generated profile images to make the websites and social accounts appear more authentic.

The network consisted of roughly 70 news sites that appeared independent on the surface but were connected to a common infrastructure, according to Anthropic.

The articles were also formatted for automated publishing and included internal links intended to improve the sites’ authority and search rankings.

This creates a worrying new dimension to AI-generated misinformation.

The problem is no longer simply that someone can ask an AI to write a fake article.

A relatively small operation can potentially create an entire synthetic media network consisting of websites, articles, fake authors and social accounts.

AI-powered surveillance is another growing concern

Anthropic also documented cases where Claude was used to process large volumes of information about individuals and identify potential targets.

In one case, an actor used AI to process social media information and create structured profiles containing details such as locations, demographic information and political leanings.

Other operations reportedly used AI to analyze hundreds of thousands of social media posts and identify accounts for monitoring.

Anthropic says one particularly sophisticated operation used Claude to help analyze information related to Uyghur targets in Syria.

The AI system was reportedly used to process information, evaluate targets and assist with deceptive messaging.

The significance is that AI can dramatically reduce the amount of human labor required to turn unstructured online information into organized intelligence.

AI is also being used to build surveillance infrastructure

The report goes beyond data analysis.

Anthropic says one consultant working for Malian national security authorities used Claude as a primary engineering resource for a surveillance platform designed to operate across the country’s mobile networks.

The platform was designed to collect telecommunications data and generate intelligence dossiers.

Anthropic says Claude was used to develop software supporting the system rather than merely analyzing information collected by it.

This distinction matters.

AI is increasingly capable of helping users build the infrastructure that performs the surveillance, not just summarize the resulting data.

The scam industry is getting an AI upgrade

Anthropic also investigated an AI-powered fake-dating operation.

According to the report, the operation combined AI-generated personas with real human workers.

The system reportedly maintained thousands of conversations using Claude, while human operators handled activities that required real people, such as live video calls.

Anthropic says Claude generated approximately 2.36 million messages over a two-week period in the operation it investigated.

The reported ratio was roughly three AI personas for every real person.

This illustrates another important pattern.

AI does not necessarily need to replace humans completely to transform fraud.

It can handle the repetitive communication while humans step in only when necessary.

That makes large-scale social engineering considerably easier to operate.

Attackers are also targeting AI itself

Perhaps one of the most consequential sections of the report concerns illicit AI model distillation.

Anthropic says it detected and disrupted campaigns in which other AI companies allegedly attempted to extract capabilities from Claude by sending large volumes of requests to the model.

The company says it attributed several campaigns to China-based AI labs.

Anthropic reports that one campaign involving Moonshot AI relayed nearly 300,000 customer requests to Claude over a ten-day period.

Another campaign attributed to Xiaomi involved more than 400,000 exchanges over 20 days.

Anthropic says the activity was designed to use Claude’s outputs as training material for other AI systems.

This is significant because the competition between AI companies is no longer only about building better models.

The capabilities of frontier models themselves have become valuable targets.

AI is entering weapons development

Anthropic’s report also documents cases involving the use of Claude for conventional weapons development.

The company says it identified six cases involving actors in China, Russia and Yemen.

The reported activities included software for guided weapons, drone systems, electronic warfare and targeting.

In one case, Anthropic says actors used Claude to help develop guidance software for a rocket and conducted a live field test.

In another, an actor used Claude to develop a software suite designed for electronic warfare and air-defense suppression.

Anthropic says its safeguards blocked many requests, but attackers attempted to bypass protections by disguising their objectives and dividing projects across multiple sessions.

That highlights a central challenge for AI safety systems.

Blocking an obviously dangerous request is relatively straightforward.

Detecting a sequence of individually harmless requests that collectively form a dangerous project is considerably harder.

Why this report matters

Anthropic’s report provides an important glimpse into how AI capabilities are changing the economics of malicious activity.

The biggest shift may not be that AI suddenly gives attackers completely new capabilities.

Instead, AI can make existing capabilities cheaper, faster and easier to scale.

A person who previously needed a team of programmers, researchers, translators, writers and analysts may be able to accomplish much more with a small group supported by AI systems.

That changes the threat landscape.

It also means traditional security models may need to evolve.

AI safety is becoming an arms race

Anthropic says the threat actors it investigated continuously tested its safeguards and attempted to circumvent them.

The company responded by banning accounts, improving detection systems and sharing relevant intelligence with authorities and other industry partners.

But the report also demonstrates why AI safety cannot be treated as a one-time engineering problem.

As models become more capable, attackers can change their techniques.

When direct requests are blocked, they can try breaking a larger objective into smaller tasks.

When one AI provider introduces stronger safeguards, attackers can attempt to use another provider.

And when one model becomes difficult to access, proxy networks and unauthorized resellers can potentially provide alternative routes.

The result is an ongoing cycle:

More capable AI → more capable misuse → stronger safeguards → new evasion techniques → stronger defenses.

The bigger threat may be AI-enabled scale

The most important takeaway from Anthropic’s report is not that AI has suddenly become malicious.

AI itself does not have an independent objective to conduct these operations.

The problem is that increasingly capable systems can amplify the capabilities of people who already have malicious goals.

That amplification can happen through speed.

It can happen through scale.

And it can happen by reducing the amount of specialized expertise required to execute sophisticated operations.

The 8,913-article influence campaign, the millions of AI-generated scam messages and the hundreds of thousands of model-distillation exchanges demonstrate different versions of the same phenomenon.

AI is making it possible to automate parts of work that previously required significant human effort.

That is enormously valuable for legitimate users.

It can also be extremely valuable for attackers.

What happens next?

Anthropic’s report suggests that the next stage of AI security will require more than simply filtering individual prompts.

AI companies will increasingly need systems capable of understanding patterns of behavior across sessions, accounts and workflows.

Governments and cybersecurity companies will also need better ways to identify AI-assisted campaigns once they move outside an AI provider’s infrastructure.

For the public, the challenge may be even more difficult.

As AI-generated content becomes cheaper to produce, distinguishing genuine journalism, authentic social accounts and real human interactions from synthetic ones could become increasingly difficult.

The AI security debate is therefore entering a new phase.

The question is no longer simply:

“What could AI do in the future?”

Increasingly, the question is:

“What are people already doing with AI today?”

Anthropic’s latest threat intelligence report provides some unsettling answers.

And if the trend continues, the ability to scale malicious activity may become one of the most important security consequences of the AI era.

Source: Anthropic’s September 2026 Threat Intelligence Report.

Related Posts

OpenAI Confirms AI Agents Hijacked German Wiki and Posted 18,000 Times

OpenAI has confirmed that a group of its AI agents were involved in a major incident involving a…

ByByBuild Bevy Sep 7, 2026

Apple Launches M6 Mac mini and M5 Ultra Mac Studio With Major AI Performance Boost

Apple has introduced a new Mac mini powered by the M6 chip and a new Mac Studio powered…

ByByBuild Bevy Aug 25, 2026

Australia Bans Fully AI-Generated Songs From Official Music Charts

Australia is drawing a clear line between music made by people and music made entirely by AI. The…

ByByBuild Bevy Aug 25, 2026

DeepSeek’s New AI Model Can See Images and Screenshots — And It’s Built for Agents

DeepSeek has introduced an experimental AI model that finally gives its V4 Flash family native vision capabilities. The…

ByByBuild Bevy Aug 22, 2026
Scroll to Top