AI appeared across the operation, not just one coding step
Anthropic published a threat-intelligence report on September 10 covering activity it detected and disrupted from December 2025 through August 2026. The seven areas are cyber operations, surveillance, influence operations, scams and fraud, biological misuse, conventional-weapons development and illicit model distillation. Suspected state-backed groups, financially motivated criminals and commercial spyware vendors appear among the actors.
The central change is the use of AI from reconnaissance and phishing-infrastructure setup through command execution, credential harvesting, lateral movement, stolen-data organization and persistence. Anthropic says one operation exfiltrated more than 300,000 national identity records and registry information for over half a million companies.
Detected Claude cases are not a census of AI crime
These are notable cases selected from activity Anthropic could observe on its own service. They do not measure the share of all attacks using AI or the counterfactual harm without Claude, and attribution and impact figures rely on the company's investigation. Most cases involved Haiku, Sonnet and Opus families; that does not establish that newer Fable and Mythos systems are risk-free.
Defenders should stop treating technical sophistication alone as proof of a well-resourced actor and instead correlate account behavior, tool calls and data movement over time. API-key protection, device-code phishing detection, export controls and monitoring how implants change after new signatures are especially relevant.