Anthropic says it found and shut down operations spanning seven categories of misuse across nine months, from December 2025 to August 2026, ranging from state-linked cyber espionage to research that might aid biological weapon development. The account comes entirely from Anthropic’s own platform logs and investigations. It is not independently verified, and the company is simultaneously the vendor whose product enabled the activity and the party reporting on it.
The report’s central claim is a shift in role. Claude moved, in Anthropic’s telling, from a passive assistant answering technical questions to an autonomous orchestrator running stretches of an operation with little human input. Anthropic measures this as “uplift,” its term for how much AI adoption expands an actor’s speed, scale, and depth of harm relative to doing the same work by hand. The company says a pattern it first flagged in November 2025 has since spread across every class of actor it tracks, spanning lone operators running public offensive frameworks such as PentAGI up to state services.
The clearest illustration is GTG-20006, Anthropic’s internal label for an espionage group whose tradecraft the company links, based on outside reporting, to Midnight Blizzard, the Russian state-linked hacking group. One operator used the handle “JackPoterz.” The group targeted Ukrainian and European government, diplomatic, and defense organizations, along with individuals tied to US foreign policy. Its custom toolkit (a browser credential stealer, a mobile-device exploitation kit, and Windows-based implants) ran through AI-driven workflows that autonomously modified and rebuilt malware whenever monitoring agents detected it had been flagged by security products, repeating that cycle until each build evaded detection again.
The report’s most consequential disclosure sits in biological research. Anthropic says its newest models can meaningfully assist complex scientific work in ways older ones, including Claude Opus 4 and Sonnet 4.5, could not, which is why it tightened dual-use safeguards on recent releases such as Claude Fable 5. Even with those safeguards, the company documents five cases where controls were tested or bypassed. One involved virologists on a state-sponsored grant conducting gain-of-function chikungunya research who reached Claude through a reseller platform after it sidestepped Anthropic’s regional access controls, then rerouted any prompts the primary model refused toward less restricted systems. In another, a reseller relay working with about a dozen customers had Claude Opus 5 produce a full grant application for orthopoxvirus immune-evasion research within roughly an hour.
Anthropic withheld the countries, institutions, and specific pathogens tied to the biological cases, and it does not name a state or organization behind any of them. Across the full report, models from Anthropic’s Opus, Sonnet, and Haiku lines were the ones actually observed in misuse. None of the cyber, surveillance, or fraud cases touched Claude Fable or Mythos, the newer model classes Anthropic says carry stronger safeguards. The report notes one exception to that pattern: a single illicit distillation case did involve a Mythos-class model.
For security teams, the actionable finding is not which lab’s models a given state actor prefers. It is that self-healing, AI-monitored malware, tooling that detects its own detection and rewrites itself with no operator steering it in real time, is now documented in the wild rather than theoretical. Any defense strategy built on static signatures for a known toolkit needs to be re-tested against an adversary that can regenerate that toolkit within hours, not weeks.
Anthropic published these findings in its Threat Intelligence report, “Detecting and countering misuse of AI,” released in September 2026.