From Russian cyber espionage and Iranian surveillance to fake news in Bangladesh, biological weapons research, and alleged AI model copying by Alibaba, Anthropic’s latest report details how AI is being misused.
Artificial intelligence is increasingly being used not just to help people carry out malicious activities, but to take over several steps of those operations, according to a new report by AI company Anthropic.
The company said it identified and disrupted attempts to use its Claude AI models for cyberattacks, espionage, surveillance, scams, influence operations, conventional weapons development and research that could potentially support biological weapons development between December 2025 and August 2026.
The cases ranged from a Russia-linked cyber espionage campaign and an automated fake-news operation in Bangladesh to systems designed to identify dissidents and attempts to use Claude in research involving viruses and toxins.
Anthropic said the actors involved included suspected state-sponsored groups, criminals, commercial spyware companies, propaganda organisations and politically motivated individuals.
The findings are detailed in Anthropic's 154-page report, Detecting and Countering Misuse of AI: September 2026, the company's fourth threat intelligence report. Anthropic said it was publishing the findings because it had a “responsibility to disclose malicious misuse” of its services.
The company said its Claude Haiku, Sonnet and Opus models were used in the cases examined. None of the cases involved Claude Fable or its Mythos-class models, except for one case involving attempts to copy the capabilities of its AI through a process known as distillation.
Across the cases, Anthropic said it has seen a change in the way AI is being misused.
The concern is no longer simply that someone can ask an AI chatbot to write malicious code or provide instructions. Increasingly, AI can be connected to other software and used to carry out several parts of an operation.
AI is doing more of the work
One of the biggest findings of the report is that AI is increasingly being used to do more than provide information or write computer code.
Anthropic said attackers are using AI to handle several parts of an operation — from finding potential targets and looking for weaknesses to stealing and processing information.
In some cases, several AI systems were used to work on different tasks at the same time, with humans setting the broad objectives and checking the results. This could make sophisticated attacks possible with fewer people and less technical expertise than would traditionally have been required, Anthropic said.
The company added that AI can also make existing attacks faster and easier to repeat on a larger scale.
Chinese-speaking group targeted about 50 organisations
Anthropic described one espionage operation involving Chinese-speaking operators it believes were likely based in Changsha in China's Hunan province.
The group used Claude in an operation targeting about 50 organisations, including companies and government agencies across sectors such as education, healthcare, finance, energy and technology.
According to Anthropic, the attackers stole hundreds of megabytes of student data from an education technology company. They also gained access to the systems of a retail company and obtained citizen records from a Southeast Asian government agency, including names, phone numbers and home addresses.
The group also used AI to look for weaknesses in security products and develop ways of exploiting them, Anthropic said.
The company said it banned accounts associated with the group and introduced additional measures to detect similar activity.
AI-generated fake news targeted rural Bangladesh
Anthropic also identified an automated operation in Bangladesh that used Claude to generate fake Bengali-language news supporting the Awami League and attacking its political opponents.
The operation was run by a single actor who used 29 Claude accounts, according to the company.
Anthropic said the actor generated at least 1,500 headlines, 300 fabricated stories and 1,500 image prompts. The material was intended for Facebook, YouTube and TikTok videos aimed at rural audiences, particularly people with limited literacy.
The actor's own communications described the material as “fake news” and said it should be “hot and aggressive” while being simple enough for village audiences to understand, Anthropic said.
The content attacked the Bangladesh Nationalist Party, Jamaat-e-Islami, the National Citizens Committee, the interim government and student protest leaders.
Anthropic stressed that it found no evidence that the Awami League itself directed or funded the operation.
The company also said some of the narratives aligned with pro-Indian geopolitical interests, but it found no evidence of state involvement or funding.
The operation was largely automated, with AI generating the material and other software turning it into videos and scheduling them for publication.
Anthropic said it banned the accounts involved and shared information about the operation with relevant platforms and other partners.
AI used to evade cyber defences
In another case, Anthropic said a group whose activity was consistent with the Russia-linked Midnight Blizzard used AI to help its malware avoid detection.
The system could reportedly identify when the malware had been detected by security software and then change the malware in an attempt to get past those defences.
The group targeted military intelligence organisations, government agencies, diplomatic organisations and defence-related companies, Anthropic said.
AI was used at several stages of the operation, including finding targets, maintaining access to compromised systems and stealing information.
Surveillance and tracking dissidents
Anthropic also found cases in which Claude was used for surveillance.
In one case, Iranian actors developed a system capable of identifying people through their social media accounts, the company said.
Another case involved a contractor working for Malian national security authorities who allegedly used Claude to develop software for an intelligence-gathering operation.
Anthropic said these cases point to a broader shift in how AI can be used in state-linked operations. “AI is now being used in place of an engineering workforce,” the company said.
AI used in biological and weapons research
The report also raises concerns about the use of AI in biological research.
Anthropic said it identified five cases involving people using its models in ways that could potentially support biological weapons development.
The research included work involving chikungunya, a highly pathogenic strain of avian influenza, viruses from families that include smallpox and mpox, as well as venoms and other toxins.
Anthropic stressed that the people involved were working scientists and that it was not claiming they intended to cause harm.
The company said biological research is particularly difficult to assess because the same information can have both legitimate and harmful uses. Research that could potentially contribute to developing a biological weapon could also be used to develop vaccines or treatments.
Anthropic also identified six cases in which Claude was used in developing software for conventional weapons, including firearms, missiles, armed drones and bombs, as well as systems used to control or target them.
Anthropic says Alibaba tried to copy Claude's capabilities
Anthropic also accused operators affiliated with Chinese technology company Alibaba of carrying out the largest attempt to copy the capabilities of its AI that it has ever measured.
The process, known as distillation, involves repeatedly asking one AI model questions and using its answers to improve another AI model.
Anthropic said Alibaba's campaign focused on Claude's ability to reason through difficult tasks. The company said the responses were collected and used to train Alibaba's Qwen AI models.
The campaign peaked at nearly three million exchanges a day, Anthropic said, involving more than 3,500 fraudulent accounts.
Between May and July 2026, Anthropic said it recorded more than 151 million exchanges that it attributed to Alibaba's activity.
The requests focused on areas such as software development, AI agents and other tasks requiring complex reasoning.
Anthropic also alleged that Alibaba used Claude to help with its own AI research and development, including work on systems used to train its models.
The company said Alibaba initially accessed Claude through nearly 5,000 fraudulent accounts, using measures such as disposable email addresses and virtual payment cards to disguise the accounts.
After Anthropic blocked those accounts, Alibaba shifted to another group of accounts, the company said.
Anthropic also accused Chinese AI firms Moonshot and DeepSeek of using Claude's outputs in similar attempts to improve their own models.
In Moonshot's case, Anthropic said nearly 300,000 customer requests were sent to its systems over 10 days through a network of 5,380 allegedly fraudulent accounts.
The company said some of those requests may have contained sensitive customer information and raised concerns about whether users knew their requests were being routed through Anthropic.
What this means
Anthropic refers to the benefit attackers get from using AI as “uplift,” essentially, how much faster, larger or more effective an operation becomes with AI.
The company said the cases in the report are not necessarily representative of everyday misuse. They are among the more significant or unusual cases identified by its threat intelligence team.
Anthropic said it had incorporated its findings into its processes “to better prevent, detect, and disrupt these activities in the future” and had shared intelligence with authorities and industry partners where appropriate.
The report comes amid growing warnings from AI researchers and industry leaders about the risks posed by increasingly capable AI systems. An Anthropic engineer, Jacob Coxon, recently stepped down after warning that AI could pose an extreme risk to humanity, including the possibility of AI killing everyone by the end of the decade.
An Anthropic safety researcher has also warned of the possibility of catastrophic harm, while OpenAI chief scientist Jakub Pachocki has called for the industry to consider “voluntary slowdowns” until adequate safeguards are in place.
But Anthropic’s 154-page report offers a picture of risks that are already playing out: AI being used to automate cyberattacks, produce political disinformation, conduct surveillance, support weapons-related work and potentially assist dangerous biological research.
The challenge for AI companies, the report suggests, is no longer only preventing models from directly providing harmful information. It is also understanding how increasingly capable AI systems can be combined with other tools and used to carry out real-world operations with limited human involvement.
This piece was first published by The News Minute. Become a joint subscriber here.