Anthropic’s September 2026 Threat Report: How Attackers Are Using Claude—and What Defenders Should Learn
Anthropic’s latest threat-intelligence report offers one of the clearest looks yet at how real-world actors are trying to use frontier AI for harmful activity. The company says that over the eight months covered by its September 2026 report, its teams identified and disrupted operations involving Claude across cyber operations, influence activity, surveillance, scams and fraud, biological misuse, conventional weapons development and illicit model distillation.
The important takeaway is not that AI has suddenly made every attacker unstoppable. It is that capable models can lower the time and expertise needed for research, scripting, persuasion and automation. That changes the economics of abuse. Defenders should respond by making common attacks harder to scale, improving identity security and monitoring for unusual automation rather than waiting for a fictional “super-hacker AI” scenario.

What Anthropic says it found
Anthropic says its Threat Intelligence team investigated misuse of Claude from December 2025 through August 2026. The company reports that it disrupted the activity, strengthened safeguards based on what it learned, and in some cases shared intelligence with authorities or industry partners.
- Cyber operations: actors attempted to use AI to accelerate parts of offensive workflows.
- Influence operations: generative systems can help produce and adapt persuasive content at scale.
- Surveillance: AI can assist in processing, organizing and interpreting large collections of information.
- Scams and fraud: language models can make social engineering more convincing and cheaper to personalize.
- Conventional weapons and biological misuse: Anthropic says it encountered attempts to obtain assistance in sensitive domains and applied safeguards.
- Illicit distillation: some actors attempted to extract model capabilities or use one model to improve another system.
The biggest shift is speed, not magic
AI systems can compress work that previously required many searches, drafts or small scripts. A less experienced operator can ask for explanations, rewrite messages in multiple tones, summarize technical documentation or automate repetitive analysis. That does not remove the need for access, infrastructure, credentials or vulnerabilities, but it can make an existing attack playbook faster and more scalable.
This is why defenders should be careful with sensational claims. The practical threat is often an ordinary attack—phishing, credential theft, fraud or exploitation—executed with better automation and personalization. Security fundamentals remain highly relevant.

Why AI-powered scams may matter to ordinary users first
For most people, the highest-probability risk is not a frontier model breaking into a national network. It is a familiar scam becoming more polished. AI can generate convincing emails, translate them fluently, adapt language to a target and rapidly produce variants that avoid looking identical.
That means the old advice “I can spot a scam because the grammar is bad” is increasingly unreliable. Users should verify requests through a second channel, treat urgent payment or password requests with suspicion, and avoid sharing one-time codes or recovery information because a message sounds professional.
What businesses should change now
- Strengthen identity controls. Phishing-resistant MFA, passkeys and hardware-backed authentication reduce the value of stolen passwords.
- Patch internet-facing systems quickly. AI may accelerate research, but attackers still need exploitable weaknesses. Our September Microsoft Patch Tuesday guide shows why timely updates matter.
- Monitor abnormal automation. Sudden bursts of logins, API calls, scraping, account creation or repetitive actions can reveal automated abuse.
- Protect help desks. Train support teams to verify high-risk account changes instead of relying on voice, writing style or a caller’s confidence.
- Control internal AI access. Sensitive company data should not be pasted into unapproved tools. Use enterprise controls and clear data-handling rules.
- Design for compromise. Segment systems and limit privileges so one stolen account cannot become a company-wide incident.

Why model providers are publishing more threat intelligence
AI companies sit at a useful observation point. They can see patterns of requests, detect policy-violating behavior and update safeguards faster than a traditional software vendor can patch millions of customer devices. Publishing anonymized case studies helps defenders understand how models are being incorporated into real operations rather than debating only hypothetical risks.
There is also a credibility challenge. Model providers have commercial incentives to portray their safeguards positively. Independent researchers, incident-response firms, governments and customers therefore remain important sources of verification. Vendor threat reports should be treated as valuable evidence, not as the only evidence.
How this connects to the wider AI slowdown debate
Anthropic CEO Dario Amodei has separately argued that frontier labs should slow capability development enough for safety controls and external evaluation to catch up. OpenAI and other industry leaders have echoed parts of that concern. Those warnings helped trigger a selloff in AI-linked stocks, which we covered in our AI slowdown and tech stocks explainer.
The threat report gives that debate a practical dimension. It shows that misuse is not only about distant superintelligence scenarios. There are already actors trying to use advanced models for fraud, cyber operations and other harmful tasks. The policy question is how to reduce those harms without blocking legitimate research and productivity gains.

What consumers should do
- Use unique passwords or passkeys and enable strong MFA.
- Verify unusual payment, password-reset and account-recovery requests through a trusted second channel.
- Keep phones, browsers and operating systems updated.
- Do not assume polished writing, a familiar voice or a realistic image proves identity.
- Report suspicious messages to the relevant service instead of only deleting them.
FAQ
Did Anthropic say Claude is being used by criminals?
Anthropic says it identified and disrupted operations in which threat actors attempted to use Claude for malicious activity. The company published case studies across seven harm areas.
Does AI make cybersecurity tools useless?
No. Strong authentication, patching, segmentation, monitoring and user verification remain effective because AI-assisted attackers still depend on access paths and weaknesses.
Is the report only about cyberattacks?
No. Anthropic’s September report also discusses influence operations, surveillance, scams and fraud, conventional weapons, biological misuse and model distillation.
Sources and references
- Anthropic — Detecting and countering misuse of AI: September 2026
- Anthropic — Threat Intelligence hub
You may also like
- AI Slowdown 2026: Why Tech Stocks Fell
- Microsoft September 2026 Patch Tuesday: Two Exploited Zero-Days
- GPT-6 Astra Explained: Features, Price and Availability
Illustrative image credits: Kevin Horvat, Jake Walker, Markus Spiske, Zulfugar Karimov and Chris Yang via Unsplash.



