LatestAnthropic says it disrupted attempts to misuse Claude — what we know (Sept 2026)

Technology

Anthropic says it disrupted attempts to misuse Claude — what we know (Sept 2026)

Attribution-led explainer of Anthropic’s Sept. 2026 disclosures about alleged misuse attempts against Claude, noting company assessments and the need for independent verification.

By Verdvit News Desk
Cybersecurity analysts review anonymized network activity in an operations room.
Verdvit editorial documentary visual

What Anthropic reported

Anthropic said its threat-intelligence team identified and disrupted attempts to misuse Claude across seven categories between December 2025 and August 2026: cyber operations, surveillance, influence operations, conventional weapons development, biological misuse, scams and fraud, and illicit model distillation.

The company described the cases as notable examples rather than typical user activity. It said the accounts involved were disrupted, lessons from the investigations were used to strengthen safeguards, and information was shared with authorities or industry partners where appropriate.

Cyber operations

One case involved an operator whose methods Anthropic said were consistent with public reporting about a Russia-linked espionage group. The company said the actor used AI-assisted workflows for reconnaissance, phishing, infrastructure management, malware modification and data handling while targeting government, diplomatic and defence-related organizations, particularly those connected to Ukraine.

Anthropic also described activity it linked to affiliates of the ShinyHunters cybercrime collective. The company said AI helped operators scan systems, identify exposed credentials and adapt to varied target environments. These descriptions are Anthropic's findings; Verdvit has not independently verified the attribution or every operational detail.

Weapons and biological-research cases

Anthropic said it identified five examples in which scientists used its models in ways that could support biological-weapons development. In one case, the company said a researcher used remote infrastructure to access Claude while planning experiments related to avian influenza adaptation. Anthropic did not identify the institution, country or specific biological agent involved.

The report also described attempts to use Claude in software development connected to conventional weapons, including targeting and control systems. Verdvit omits actionable technical details and presents the cases only at the level needed to explain the stated safety concern.

Model-distillation allegations

Anthropic alleged that seven China-based laboratories attempted to extract Claude's capabilities through prohibited model-distillation activity. Reuters reported that several named companies did not immediately respond. China's foreign ministry said it was not aware of the report, supported developing AI for good and opposed distortion and smears.

Why attribution matters

This article reports a company's threat-intelligence assessment, not a court finding or independent technical audit. The report offers useful evidence about how a model provider says its systems were misused, but readers should distinguish observed platform activity, the company's actor assessments and allegations concerning external organizations.

Related coverage

Verdvit's earlier AI policy brief covers calls for international safeguards without offering operational cyber guidance.