Anthropic’s September 2026 Threat Report: Russian Spies Used Claude Against 20+ Targets

Sanket Chaukiyal

September 13, 2026

TL;DR

  • Anthropic’s September 2026 Threat Intelligence Report covers misuse it disrupted between December 2025 and August 2026, eight months in the field.
  • The report spans seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation.
  • A Russian espionage campaign tracked as GTG-20006, tied to Midnight Blizzard, used Claude against more than 20 organizations, including Ukrainian government bodies and drone supply chain firms.
  • Anthropic says every case ended the same way: activity disrupted, safeguards strengthened, intelligence shared with authorities and industry partners.

What Anthropic Actually Found

Anthropic dropped its September 2026 Threat Intelligence Report this week, and it reads less like a marketing document and more like a case file. The company says its Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity over the past eight months, from December 2025 through August 2026.

The report groups the misuse into seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. That’s a wider net than Anthropic cast in its earlier reports from March, August, and November 2025, and it signals the company is tracking more categories of abuse as its models get more capable and more widely deployed.

Three model families sit at the center of the findings: Claude Haiku, Sonnet, and Opus. Anthropic’s newer Fable and Mythos-class models barely show up in the data, appearing in just one distillation case. Whether that’s because those models are harder to misuse, less accessible, or simply too new to have accumulated a track record is left unanswered.

The headline case study is GTG-20006, an operation Anthropic ties to the Russian state-linked group Midnight Blizzard, also tracked under the alias JackPoterz. According to the report, this group used Claude to help run an espionage campaign against more than 20 organizations, including Ukrainian government agencies and companies in the drone supply chain. It’s the kind of detail that turns an abstract worry about AI misuse into something with a map and a target list.

Anthropic says the pattern held across every case in the report, regardless of who was behind it: “In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate.” State-sponsored operators, financially motivated fraud rings, spyware vendors, and lone hacktivists all show up in the same document, which itself says something about how flat the misuse landscape has become. You don’t need a nation-state budget to try to weaponize a chatbot anymore.

The Uncomfortable Pattern Anthropic Keeps Finding

I’ve read three of these reports now, and what strikes me isn’t the sophistication of the attacks. It’s the sameness. A Russian intelligence unit and a random scam artist end up in the same document because they’re both just trying the same trick: getting a capable model to do the tedious parts of an attack so a human doesn’t have to.

Think of Claude here less like a weapon and more like a very fast, very literal contractor who doesn’t ask why you need a hundred fake documents drafted by lunch. The contractor isn’t malicious. It just does the job it’s told, quickly, at scale, without getting tired around hour six. That’s what makes the GTG-20006 case worth sitting with: 20-plus organizations targeted, Ukrainian government bodies and drone supply chain firms among them, all through an operation that leaned on Claude to move faster than a human-only team could.

Does publishing this make Anthropic safer, or does it just make Anthropic look responsible while the underlying dynamic keeps repeating every few months? Probably both. The company gets credit for transparency, and it should. Naming Midnight Blizzard, describing distillation attempts, and detailing biological and weapons-related misuse is not the move of a company hiding a problem. But transparency isn’t the same as solving it.

The seven harm areas in this report are also a tell. Anthropic isn’t just watching for hacking anymore; it’s watching for influence operations, surveillance tooling, and scam infrastructure, categories that barely registered in the AI-safety conversation two years ago. That expansion tells you the threat surface is growing faster than the defenses, even as the defenses improve. And the fact that Fable and Mythos models barely appear in the data is its own small mystery. Are they actually safer, or just less discovered?

A Report That Keeps Getting Longer

This isn’t Anthropic’s first rodeo with this kind of disclosure. The company published threat intelligence reports in March, August, and November of 2025, each one documenting a slice of real-world misuse as it happened. The September 2026 edition is the fourth in that lineage, and it covers the longest window yet: eight full months of disrupted activity.

What’s changed between those earlier reports and this one is scope. Early reports leaned heavily on cyber operations and scams. This one folds in biological misuse and conventional weapons development as standing categories, not one-off mentions. That shift mirrors a broader industry conversation about frontier models and dual-use risk, the kind of concern regulators in Washington and Brussels have been circling for a while.

Anthropic frames all of this within its stated approach: catch misuse, learn from it, tighten the model’s guardrails, then tell people what happened. Whether that cycle is fast enough to outrun the actors adapting around it is the real question sitting underneath every one of these reports.

What To Watch From Here

The next report, whenever it lands, will be the real test of whether this pattern is shrinking or spreading. If the harm-area list grows past seven, that tells you Anthropic’s detection is outpacing its containment. If it shrinks or stabilizes, that’s a rare good sign in this space.

Keep an eye on the Fable and Mythos-class models too. Right now they’re barely present in misuse data, but that could just mean smaller deployment footprints rather than better defenses. A future report showing those models catching up to Haiku, Sonnet, and Opus in case counts would be a meaningful signal worth flagging.

And watch what happens with intelligence sharing. Anthropic says it passes findings to authorities and industry partners when appropriate. Whether that turns into coordinated action against groups like Midnight Blizzard, or just stays a paper trail inside individual companies, will say a lot about whether the AI industry’s self-policing actually holds up under pressure.

Editor's Note

What gets me about this report isn't the Midnight Blizzard case, striking as it is. It's how ordinary the list has become. State spies, scam artists, and hacktivists sitting in the same document, all trying the same basic move. I keep waiting for Anthropic's disclosures to shrink the harm-area list instead of growing it. They haven't yet. I'll be watching whether the next report finally shows containment winning, or whether transparency just becomes the industry's favorite substitute for it.

– Sanket Chaukiyal, founder, SmartChunks

FAQ

What is Anthropic's September 2026 Threat Intelligence Report?

It's Anthropic's fourth public disclosure detailing real-world misuse of its Claude models. It covers disrupted operations between December 2025 and August 2026 across seven harm categories, including cyber operations, espionage, and biological misuse.

What is GTG-20006?

GTG-20006 is the case study Anthropic ties to the Russian state-linked group Midnight Blizzard, also referenced as JackPoterz. The report says this group used Claude to support an espionage campaign against more than 20 organizations, including Ukrainian government bodies and drone supply chain companies.

Which Claude models were involved in the disrupted misuse?

The report says Claude Haiku, Sonnet, and Opus were the models actually misused in the documented cases. Anthropic's Fable and Mythos-class models appeared in only one instance, tied to an illicit distillation attempt.

Did Anthropic stop the misuse it found?

According to the report, yes, in every case. Anthropic says it disrupted the activity, used what it learned to strengthen safeguards, and shared intelligence with authorities and industry partners where appropriate.

Sanket Chaukiyal — Editor at Smart Chunks

Sanket Chaukiyal

Technology editor • 12+ years in editorial

Sanket is the founder and editor of Smart Chunks. He spent over six years at Autocar India (Haymarket SAC Publishing) as Sub Editor and Senior Copy Editor, and later served as Account Director (Content) at Rite Knowledge Labs. He holds a Master's in Media and Communication from the Symbiosis Institute of Media and Communication.

All articles → LinkedIn