Anthropic says it has disrupted cyber operations in which artificial intelligence moved beyond assisting human hackers to orchestrating reconnaissance, exploitation and data theft, alongside alleged efforts by seven China-based AI labs to extract capabilities from Claude.

The findings appear in Anthropic’s September 2026 threat intelligence report, which covers cases the company said it detected and disrupted between December 2025 and August 2026. The report includes cyber operations, surveillance, influence campaigns, conventional weapons development, biological misuse, scams and fraud, and illicit model distillation.

Anthropic said the cases were selected as notable or novel examples rather than a representative sample of misuse on its platform. Most involved Claude Haiku, Sonnet and Opus models, while none involved Fable or Mythos-class models apart from one distillation case, according to the company.

Russian-linked campaign targeted more than 20 organizations

One operation, tracked by Anthropic as GTG-20006, allegedly used customized AI-driven workflows across much of the attack process. Anthropic said the actor’s tradecraft and targeting were consistent with a Russia-linked espionage group publicly tracked by Microsoft as Midnight Blizzard.

The actor used AI to research targets, configure phishing infrastructure, execute parts of intrusions, harvest credentials, move laterally through networks, organize stolen data and maintain access to compromised accounts, the report said. Anthropic also described agents that monitored whether security products detected the actor’s malware, then modified and rebuilt the code until it evaded those detections.

Anthropic identified more than 20 organizations in the actor’s planning, reconnaissance or live operations. Targets were concentrated in Ukraine and Europe and included government ministries, defense and intelligence bodies, diplomatic missions, think tanks and companies in the defense supply chain.

The target list also included an unnamed Southeast Asian government entity connected to maritime shipping and tracking, according to the report. Anthropic did not identify the country, agency, date of the activity or whether the entity was compromised.

Reuters noted that the US government has previously linked Midnight Blizzard to Russia’s SVR foreign intelligence service. The Russian Embassy in Washington did not immediately respond to Reuters’ request for comment.

Anthropic alleges distillation AI labs

A separate section alleges that seven laboratories conducted unauthorized campaigns to copy capabilities from Claude’s generally available models. Distillation is a legitimate method in which outputs from a larger model help train a smaller one, but Anthropic defines illicit distillation as covert extraction carried out at industrial scale without authorization.

Vendor telemetry shapes the report’s limits

Anthropic said it banned accounts tied to the operations, strengthened classifiers and safeguards, and shared intelligence with authorities or industry partners where appropriate. It did not disclose a complete list of victims, enforcement dates or the evidence used for every attribution.

The company has direct visibility into activity on Claude, but the report remains a vendor-authored account. Outside researchers do not have access to the underlying account data, prompts, network indicators or enforcement records needed to reproduce its findings.

The cases nevertheless show how agent frameworks can reduce the labor required to run complex operations. Human operators in the incidents described by Anthropic still selected targets and reviewed results, while AI systems executed or coordinated an expanding share of the technical work.

For organizations in Southeast Asia and the wider region, the unnamed maritime target illustrates potential exposure across public-sector and critical-infrastructure systems. The report provides no evidence that other Southeast Asian entities were involved in the cited campaign.

ESET survey says 79% of Singapore organizations faced AI-related cyber threats