Anthropic AI Exploited for Hacking… Russian Intelligence and Chinese Hacker Cases Revealed [Claude AI Misuse Report ①]

Photo of author

By Global Team

Anthropic published a 154-page report titled Detecting and Preventing AI Misuse, September 2026, on September 10 (local time). The document summarizes cases in which its AI model Claude was used for malicious activities from December 2025 through August of this year.

The report covers seven areas: cyber operations, influence operations, surveillance, conventional weapons, biology, fraud, and unauthorized model distillation.

The key change in the cyber field was not the attack methods themselves, but their cost and speed. Anthropic assessed that AI had sharply narrowed the gap in manpower and tools that once separated state-level organizations from individual attackers.

Anthropic published the 154-page report “Detecting and Preventing AI Misuse, September 2026,” detailing cases in which its AI Claude was used for malicious purposes.
Anthropic published the 154-page report “Detecting and Preventing AI Misuse, September 2026,” detailing cases in which its AI Claude was used for malicious purposes.

AI misuse is no longer merely a possibility. Actual cases have emerged involving hacking and espionage, influence operations, surveillance, weapons, and biological research. Anthropic’s 154-page report shows how AI is changing the speed and scale of existing threats. Based on the report, this article examines how AI is being used in criminal activity and state operations.

On September 10 (local time), Anthropic published a 154-page account of how its own products had been misused.

The document is notable because of its source. Until now, the reality of AI misuse had largely been estimated from the outside. This time, the company that developed the models documented what it observed internally. The report describes who entered which prompts and where the models refused to comply. The models misused were Haiku, Sonnet, and Opus. The report explicitly states that “apart from one case involving illegal distillation, there were no misuse cases involving models at the level of Fable or Mythos.”

◆ The conclusion: “The skills gap has disappeared”

AI has eliminated the skill gap among hackers. That is Anthropic’s conclusion.

In the past, only state-level organizations with sufficient money and personnel could carry out sophisticated attacks. The implication is that individual hackers can now conduct attacks at a comparable level.

No new hacking techniques have emerged. The report states: “The attacks themselves are familiar: stolen credentials, unpatched devices, exposed services, SQL injection, and phishing.” In other words, the methods remain the same as before.

What has changed is the cost. AI now handles labor-intensive tasks such as reconnaissance, intrusion, tool development, and data organization. That labor previously translated directly into expense, a burden only state-level organizations could afford. As that barrier has fallen, some intrusions have been completed within two to three hours, while a single hacker has been able to manage dozens of victims simultaneously.

Humans have not disappeared entirely. The report says that “humans remain deeply involved in deciding whom to target, how to monetize the operation, and whether the results are accurate,” adding that “some of the most serious breaches came from operations in which humans directed every step.”

Below is a representative example among the six cyber operations cited in support of this conclusion.

◆ Russian espionage group automatically modifies malware

The first case involved a Russian state-linked espionage organization. The report code is GTG-20006. Anthropic assessed that the group corresponds to an organization publicly known as Midnight Blizzard.

The targets included government agencies and military, intelligence, diplomatic, and defense organizations in Ukraine and Europe. Individuals connected to U.S. foreign policy were also targeted.

The organization automated a substantial portion of its attacks with AI. AI monitored whether the malware had been detected by security products. When detection was confirmed, an AI agent modified and rebuilt the malware to evade the existing detection, repeating the process until the malware was no longer detected.

The attack routes were varied. The group compromised at least three companies operating Wi-Fi networks for hotel guests and altered their DNS settings. It then redirected guests to servers under its control, delivering malware targeting Windows, Android, and iOS devices.

It also hijacked WhatsApp accounts. To make the theft less noticeable, it concealed read receipts while collecting large volumes of conversations in Russian and Ukrainian. At least two former senior Ukrainian officials were among the targets.

The drone supply chain was another major target. The group extracted large volumes of emails from at least two drone-parts manufacturers and also targeted a military drone company. After stealing an entire proprietary software development kit for a drone video system, it analyzed the product architecture, component configuration, and supply-chain information.

At a government technology agency in North Africa, the group stole more than 300,000 national identity records and commercial registration data on more than 500,000 companies.

◆ Reverse-engineering 1.8 million apps

The second case involved a cybercrime organization motivated by financial gain. The report code is GTG-50014.

Anthropic tracked several attackers linked to ShinyHunters. One French-speaking operator used 10 AWS servers to run a large-scale credential-collection system.

The system downloaded 1.8 million Android app installation files from multiple app stores. It automatically decompiled them and searched the code for access information, including exposed passwords and API keys. The findings were sent to Telegram in real time.

The attackers used the information to carry out actual intrusions. More than one terabyte of data was taken from a technology services company, including hundreds of thousands of national identification numbers and millions of payment-card records. At an airline, the attackers accessed a system containing tens of millions of passenger records.

The intrusions were also rapid. At one enterprise software company, only a few hours passed between initial access and the theft of large volumes of data. In another case, the attackers began with a single stolen developer token and took approximately three hours to obtain full administrator privileges across the victim company’s cloud environment.

Anthropic compared this attack method to “vibe hacking.” Once an attacker provides a broad objective, AI examines the environment and writes scripts, then repeatedly executes, checks the results, and makes corrections. This allows an attack to continue even when the attacker does not fully understand the structure of the victim’s systems.

◆ Chinese university students create a zero-day factory

The third case involved a Chinese-speaking organization. The report code is GTG-10007.

Anthropic assessed that the operators were likely located in Changsha, Hunan Province, China. Two of the operators were identified as undergraduate students studying computer and communications engineering at a university in Hunan.

The organization used Claude not only to build attack tools but also to design and operate the entire campaign. It divided reconnaissance and intrusion into foreign government agencies, vulnerability research on security products, malware development, and intelligence collection into separate tasks and ran them simultaneously. Some systems continued operating even when the operators were away.

The vulnerability research process was also automated. After decompiling the firmware and software of network devices, the AI analyzed their structures, developed vulnerability hypotheses, wrote exploit code, and tested it in laboratory environments. When the tests failed, it modified the code and repeated the process until it succeeded.

Using this approach, the group discovered more than a dozen potentially zero-day vulnerabilities in one month. Some previously unknown vulnerabilities were verified by the attackers in their own test environments.

AI was also used for intelligence collection. Thirteen continuously operating AI collection agents gathered information on schedules from publicly accessible U.S. military and government websites, contract announcements, and other sources. The overall targets included approximately 50 organizations across education, retail, energy, technology, health care, finance, manufacturing, and government.

Actual damage occurred. At an education technology company, hundreds of megabytes of students’ personal information were taken. At a government agency in Southeast Asia, the attackers obtained citizen records containing names, telephone numbers, and addresses.

◆ One hacker attacks Europe’s political sector

Anthropic also identified a case in which an individual hacker used AI to attack multiple organizations simultaneously. The report code is GTG-50029. Anthropic identified the person as a French-speaking lone attacker and did not disclose any separate organization or affiliation.

This year, the attacker targeted European political parties, media organizations, and think tanks in succession. The SaaS providers used by those organizations were also targeted. The attacker created a proprietary search tool to locate exposed API keys and assigned reconnaissance, code review, and vulnerability verification to multiple AI agents.

Using Claude, the attacker also discovered a previously unknown vulnerability in the WordPress reinstallation process. Claude was used to write and test the attack method as well. The attack succeeded against at least four websites.

The damage extended to politically sensitive information. On a political campaign management platform, the attacker extracted approximately 140,000 records containing users’ political views.

Anthropic highlighted the fact that the attacker was working alone. The individual delegated reconnaissance, vulnerability analysis, and attack-code development—tasks that could previously have been divided among several people—to AI agents. The report described it as a case in which an individual attacker used AI to expand the scale of an operation.

◆ Thirty AI companies attacked

AI companies and even AI models that have not yet been publicly released became targets of a criminal organization. The report code is GTG-50020.

The attack was carried out by a Russian-speaking criminal organization. The group had previously focused mainly on hotel-booking and fintech companies but later expanded its targets to the AI industry.

The first attack targeted an AI company’s automated evaluation system. The attackers inserted malicious instructions into an evaluation sandbox and stole API keys belonging to multiple AI companies. The acquired keys were then used in subsequent attacks.

The attacks spread quickly. Over approximately four days, the organization repeatedly attempted the same method against 30 AI companies. It slightly modified an attack route discovered at one company to fit the environments of other companies.

The ultimate goal was to access an unreleased Claude model. The group tried more than 10 routes to do so, but all attempts failed. Anthropic’s own systems were not directly breached. All of the API keys used in the attacks had been stolen from customer environments.

Anthropic assessed that the incident showed how the AI industry’s supply chain itself has emerged as a target for criminal organizations. Attackers do not need to hack an AI model directly; they can first compromise connected elements such as a customer’s API keys or an evaluation system.

◆ Account theft using a fake Claude service

Criminal activity using Claude as bait also emerged. The report code is GTG-50021. The perpetrators sold a fake service advertised as offering inexpensive access to Claude.

What users actually received, however, was not Claude. Their prompts were secretly forwarded to another AI model. The installation program also contained a hidden function that stole Anthropic account credentials.

The stolen credentials were resold to other AI resellers. The accounts and API keys acquired in this way allowed attackers to use AI without spending their own money. They also helped disguise criminal activity as usage by legitimate customers.

Anthropic warned that AI accounts and API keys should be managed like passwords or cloud-access credentials. It recommended avoiding resellers of uncertain origin and using official sales channels.

◆ AI lowers the cost of hacking

The common thread across the cyber cases in the report is not the emergence of new hacking techniques. Rather, existing attacks can now be carried out more quickly and with fewer people.

AI is taking on a broader range of tasks, including reconnaissance, vulnerability analysis, attack-code development, intrusion, and the organization of stolen data. Cases have emerged in which individual attackers simultaneously run tasks that were once divided among several people. Some intrusions were completed in just two to three hours.

Anthropic concluded that the manpower and tool advantage once separating state-sponsored organizations from individual attackers is breaking down. It is becoming difficult to judge the size or capabilities of an operation simply from the sophistication of its attack. The distinction between state-level organizations and small criminal groups is increasingly based on the purpose of an attack rather than technical ability.

Human involvement, however, has not disappeared. People still decide which targets to pursue and what information to steal. AI has not replaced attackers so much as served as a tool for increasing the speed and scale of attacks.

Anthropic said it had blocked the activities it detected and incorporated the findings of its investigations into its safety measures. When necessary, it also shared relevant information with authorities and industry partners.

The cases included in the report do not represent the general pattern of Claude misuse. Anthropic explained that it selected and disclosed cases that were particularly notable or represented new threats among those it has identified to date.

The purpose of publishing the report was also clear. Anthropic said it wanted to help other AI developers identify similar misuse patterns on their platforms and help governments and civil society understand emerging threats. The report also reflects an effort to strengthen joint responses to AI misuse.