.png)
Between December 2025 and August 2026, Anthropic’s Threat Intelligence team tracked and disrupted AI misuse across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and model distillation. The cases involve suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, propaganda institutions, and politically motivated individuals.
The report is not a catalogue of typical abuse. It is a set of novel cases — and read as a defender, the through-line is uncomfortable: the economics of offense have changed, and most SOC operating assumptions were calibrated to the old economics.
The first shift is the most operationally significant. In cyber operations, AI use has moved from conversational assistance toward direct execution and orchestration. Most operations in the report involved multi-agent frameworks conducting reconnaissance, exploitation, and data exfiltration.
Humans still set targets and review results, but some operations ran autonomously for hours or days. Anthropic’s framing is blunt: autonomy multiplies the speed, scale, and efficiency of an operation.
For anyone running detection engineering, that sentence is the whole report. An intrusion where recon-to-exfiltration is an agent loop rather than a human at a keyboard does not respect the tempo assumptions baked into tiered triage. Dwell time shrinks, but so does the analyst’s window to act inside it. If your MTTD is measured in hours and the adversary’s kill chain now completes in minutes of machine time, the metric is still green while the outcome is already lost.
The second shift is about who can run these operations. The report says AI has collapsed the labour and tooling gap between well-resourced state operations and individual operators. Reconnaissance, tool development, data processing, and exploitation have all been uplifted.
Anthropic first documented this operating model in November 2025 for largely autonomous attacks. It has since proliferated across every class of actor the company has investigated.
The practical consequence: threat modelling that segments adversaries by resourcing — APT here, commodity crime there — loses predictive value. Capability no longer tracks budget. A single operator can now produce artefacts that, on TTP analysis alone, look state-grade.
Influence operations increasingly use AI to build both the content and the apparatus behind it: fake social media profiles, fake news sites, fabricated dossiers, and commercial influence-as-a-service offerings. Claude was used as a sub-editor or content creator, with persistent files supporting repeatable workflows. The report also observed deliberate attempts to launder attribution, sourcing, certainty, and the identities behind narratives.
On surveillance, between January and July 2026, state-aligned actors, contractors, and commercial spyware vendors used Claude to facilitate surveillance operations — AI replacing parts of an engineering workforce, processing large volumes of social media data, identifying targets, and supporting state security workflows. In one case, an AI assistant helped a PRC intelligence unit produce thousands of investigations per month.
Scams scale the same way. A China-based app studio used Claude to build more than 20 dating apps and power AI personas while advertising the services as fully human. Over two weeks in April 2026, more than 4,700 distinct AI personas conversed with at least 25,000 people, mixing AI personas with real workers and drawing on multiple AI providers for different roles.
The category most likely to be ignored by security teams is the one with the clearest enterprise blast radius. Anthropic defines illicit distillation as an industrial-scale, covert campaign to extract a model’s capabilities and replicate them elsewhere without authorization — commonly using fraud: fake accounts, stolen credentials, credit cards, or API keys. Targets are the valuable frontier capabilities: agentic functions, tool use, coding, data analysis, logical reasoning.
The scale is the headline. Alibaba’s campaign — the largest Anthropic had measured — peaked at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts, targeting agentic, software engineering, kernel development, and long-horizon tasks. Between May and July 2026, more than 151 million exchanges were attributed to Alibaba, with transcripts used to advance model reasoning.
And distillation is not a victimless IP dispute. Moonshot AI silently forwarded customer requests to Claude instead of processing them through Kimi — nearly 300,000 requests relayed over ten days — and Anthropic says some of those rerouted requests contained sensitive customer information. A separate Xiaomi campaign replayed user conversations and coding sessions through Claude, including sensitive user data.
If your organisation has adopted an AI vendor without contractual and technical assurance about where inference actually happens, that is a third-party data-flow risk hiding inside a procurement decision.
Across these cases, one thing stands out to me: attackers are not simply using AI to do the same work faster. They are changing how the work gets done.
We've spent years building security operations around a relatively human attack cycle. When parts of that cycle become autonomous, those assumptions start to break down.
The practical question for defenders is:
Which parts of our defensive workflow are still dependent on human-speed processes when the activity we're trying to detect may not be?
That means:
The same thinking applies to AI vendors. As more sensitive data and business processes move through third-party AI systems, security teams need to understand where data goes, which models process it, what agents can access, and whether other providers sit downstream.
These are becoming security operations questions, not just AI governance questions.
For me, that is the real lesson from the report. AI is changing attack economics, not simply accelerating individual steps. If offensive operations can run at agent speed and agent scale, defensive operations need to adapt too — using AI and automation to monitor, investigate, and respond faster while keeping human expertise where it matters.
The objective isn't to match attackers with more AI for the sake of it. It is to build security operations that can understand, act, and adapt at the speed of the environment they are defending.
Anthropic Threat Intelligence report covering December 2025 – August 2026.
