Anthropic: AI lets lone hackers run state-grade cyberattacks
Detecting and countering misuse of AI: September 2026

Anthropic's September 2026 threat intelligence report reveals that AI has collapsed the skill and resource gap in cyber operations. Over eight months, the company disrupted campaigns where actors used Claude to automate reconnaissance, exploitation, and data theft. A Russian state-linked group, GTG-20006, built AI workflows that autonomously rebuilt malware to evade detection, targeted Ukrainian drone supply chains, and stole over 300,000 national identity records from a North African government. The report warns that sophistication is no longer a reliable signal of who is behind an attack.
Sophisticated attacks no longer require sophisticated attackers.
- tedsanders
Meta: The potential proliferation of biological weapons is serious. Millions could die. It's easy to joke about before it happens, but try to imagine how this thread might look after the successful deployment of a biological weapon by a rogue state or non-state actor. I encourage you to take this topic seriously and contribute posts that add new information or perspectives to the discussion.
(I myself think the odds of a bioweapon attack remain low and have not yet been seriously accelerated by LLMs, but this is absolutely something the world should pay attention to.)
- m-hodges
> We discovered that Moonshot AI, the company that produces the Kimi family of models, silently forwarded customer requests to Claude, instead of processing them using Kimi. Moonshot then displayed Claude’s responses to users. These users thought they were using a Kimi model, but received responses from Claude instead.
> DeepSeek also silently relayed exchanges to Claude without informing DeepSeek customers.
> MiniMax built its own proxy network service through a shell company. This shell company has no obvious links to MiniMax and does not disclose its relationship to its parent company. This shell proxy network service only offers access to models developed by Anthropic and OpenAI. The service does not offer access to any Chinese models, including Minimax’s own.
- hnburnsy
Quite the double standard here...
Conventional Weapons
-We identified a cell of threat actors based in northern Yemen
-We identified a China-based threat actor who used Claude
-We identified likely freelance Russia-based threat actors
-We identified a China-based actor who used Claude’s chat
-In this case, a Russia-based actor used Claude
-We identified a China-based threat actor who used Claude
Biological misuse
We are withholding the names of research institutions, the countries wherein the activity took place, and the specific biological agents or research techniques involved. The individuals implicated in these case studies are working scientists. We do not assert that they intended harm, and identifying them or their labs could expose them to harm.
- nhinck2
> Illicit distillation
Really... what makes it illicit?
- oidar
It also blocks my ability to talk about Emily Dickinson in other languages/scripts. Apparently,the poem: "Because I could not stop for Death" is too dangerous.
- The_Blade
the inline link to the page to the report was Slashdotted for a moment (yesssssss), but here is the report directly now:
https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a...
- bix6
I’m so curious how they monitor users. Like that person the other day talking about Claude helping with their torrent stack, will Anthropic report them for breaking the law?
- Sol-
I will admit I asked Fable about Mitochondria.