
Anthropic has published a new threat intelligence report, and the message is clear enough: AI misuse is no longer a theoretical risk waiting somewhere in the future. It is already happening, and the better question now is how quickly AI companies can detect and stop it.
In its September 2026 threat intelligence report, Anthropic says it disrupted attempts to misuse Claude across cyber operations, surveillance, influence operations, scams and fraud, conventional weapons development, biological misuse and illicit distillation. The company says the activity covered the period from December 2025 through August 2026.
The report is important because Anthropic is not simply warning that someone might misuse AI one day. It is describing cases it says its own threat intelligence team found and stopped. The company says it banned accounts, strengthened safeguards, and shared intelligence with authorities and industry partners where appropriate.
One of the strongest points in the report is that AI is changing the economics of cybercrime. Anthropic says sophisticated attacks no longer require the same level of sophisticated operators because AI can help attackers move faster across reconnaissance, tool development, data processing, exploitation and exfiltration.
That is the part ordinary businesses should pay attention to. A small group with limited technical depth can now use AI to understand unfamiliar systems, write scripts, scan for credentials, organise stolen data and adapt tools more quickly than before. The gap between a well-resourced attacker and a motivated lower-skilled attacker is narrowing.
Anthropic says several operations moved beyond simple chatbot use and involved AI orchestration. In some cases, threat actors used multi-agent workflows for reconnaissance, exploitation and data exfiltration, while humans remained involved in choosing targets and reviewing stolen material.
The Russian espionage case in the report is especially serious. Anthropic says the actor used AI-driven workflows to automate parts of phishing, malware development, infrastructure setup, persistence and exfiltration. The targets included Ukrainian and European government, diplomatic and defense-linked organisations, with interest in drone technology and supply chains.
The report also says a North African government technology authority was compromised in one operation, leading to the theft of more than 300,000 national identity records and commercial registry data for more than half a million companies. That detail makes the story relevant beyond the US and Europe because state data systems across emerging markets could become softer targets for AI-assisted operations.
Financially motivated hackers also appear in the report. Anthropic describes suspected ShinyHunters-linked activity involving credential harvesting, cloud compromise, data theft and extortion. In one case, the company says AI agents performed nearly all of the work during parts of an intrusion and data-theft operation.
This connects directly with the security stories we have been following. OpenAI’s Hugging Face incident showed how AI agents can coordinate and behave in ways their creators did not intend. We covered that wider concern in our article on the 700-agent Hugging Face breach. Anthropic’s report now adds another layer: outside actors are also learning how to use AI as operational infrastructure.
The surveillance section is also troubling. Anthropic says it disrupted activity involving systems designed to identify and monitor dissidents. That is where AI misuse moves from technical abuse into human-rights risk. A model that can process language, images, social posts and identity clues at scale can become a powerful tool in the hands of a repressive actor.
The influence-operation angle should not be ignored either. Elections, public trust and information ecosystems are already under pressure from bots and coordinated campaigns. AI makes content cheaper, faster and more personalised, which means influence operators can test messages, translate propaganda and scale fake personas with less effort.
Anthropic also included scams and fraud in the report, and this is where most everyday users may feel the impact first. AI can make romance scams, fake job offers, cloned customer support messages and phishing attempts more believable. The language becomes cleaner, the targeting becomes sharper and the attacker can run more conversations at once.
For Africa, the lesson is immediate. Banks, telecoms, government agencies and fintechs are digitising faster than many security teams can mature. We recently wrote about the CBN warning banks and fintechs to treat cyber risk as a financial stability issue. Anthropic’s report shows why that warning is not abstract.
There is also a responsibility question for AI companies. Anthropic deserves credit for publishing detailed misuse findings, but transparency cannot be a substitute for prevention. As models become more capable, the industry will need stronger abuse monitoring, faster account takedowns, better sharing of threat intelligence and clearer limits around agentic cyber capabilities.
Governments also need to understand that AI safety is not only about future superintelligence. It is about present-day criminals, spyware vendors, state-backed groups and scammers using models to reduce the cost of harm. Rules that focus only on chatbots will miss how AI is actually being used in the field.
The difficult truth is that the same qualities that make Claude and other advanced models useful also make them attractive to bad actors. They can read, reason, code, summarise, translate and operate across complex tasks. Those abilities are valuable for defenders, but attackers are learning to use them too.
Anthropic says none of the misuse cases involved Claude Fable or Mythos-class models, except for one illicit distillation case. That distinction matters for Anthropic’s product positioning, but it does not weaken the bigger point. Even non-frontier models can create real uplift for malicious users when placed inside the right workflow.
The report should therefore be read as a warning to the whole industry. AI abuse is becoming more organised, more autonomous and more operational. Foiling these campaigns is good, but the real test is whether the next wave can be detected before victims lose data, money, privacy or national-security secrets.







