Cyber operations
AI makes old techniques run faster: stolen credentials, unpatched systems, and phishing are still the entry points. What changes is scale and cost.
Public threat report · Independent analysis
Independent case analysis based on public threat reports. We've organized Anthropic's threat intelligence report into 42 cases, each explaining what happened, what role AI played, what evidence exists, and what remains unknown. This is an independent editorial project, not an official Anthropic website.
Language: 简体中文 · English · Español · Français · العربية · 日本語
Read by mechanism of harm, not by country or company ranking.
AI makes old techniques run faster: stolen credentials, unpatched systems, and phishing are still the entry points. What changes is scale and cost.
What matters isn't the viewpoint, but hiding identity, concealing sponsorship, and disguising sources. Volume doesn't equal how many people were actually reached.
Publicly available data does not mean it can be linked, identified, and tracked without consent.
Documents, simulations, and tests must be read separately: having software or specifications does not mean a real strike capability exists.
The same body of knowledge can be beneficial or harmful. This site only covers use categories, stages, and governance — never any experimental details.
The person on the other side may not be who you think: the report says some dating apps mix undisclosed AI identities into 'real-person services' and push users to pay.
Distillation is a technique; unauthorized access, forwarding, and data extraction are a separate judgment. The report's allegations are not legal conclusions.
Three representative cases: fraud targeting ordinary people, credential theft in the AI service supply chain, and organized influence operations.
01Scams & fraud
According to an Anthropic report, a Chinese app studio used Claude to build a network of more than 20 dating apps and power AI virtual identities that conversed with users — even though its services were advertised as entirely human-run. In a two-week window in April 2026, the report found more than 4,700 distinct AI virtual identities interacting with at least 25,000 unique individuals. The studio also recruited real people to mix into the same matching feed as the bots, mainly for authenticity checks. The ratio of AI to humans was roughly 3:1.
02Cyber operations
According to Anthropic's report, the AI supply chain has become a target, loot, and source of attack compute for malicious actors. AI access in the form of stolen API keys, session tokens, and devices is increasingly the sole objective of multiple criminal groups. GTG-50021 is a fake AI reseller service operated by a Russian- and Ukrainian-speaking actor. Customers thought they were buying discounted Claude access, but their traffic was silently routed to other models; the reseller tool also installed a credential collector on the device, reselling account credentials to other proxy networks.
03Influence operations
According to Anthropic's report, a network disguised as 'independent local newsrooms' used Claude to mass-produce and rewrite political content: about 70 fake news websites, at least 8,913 articles, about 20 languages, plus 70 associated X accounts and over 250 fake comment accounts for amplification. But the report also emphasizes: most content had almost no real audience engagement, and no evidence of spread beyond its own network was found — output volume is not the same as influence. The report traced the network to a French digital advertising company, could not confirm the paying clients, and found no evidence of any government direction.
Currently featuring one report: Anthropic's *Detecting and countering misuse of AI: September 2026*, released September 10, 2026, 154 pages, in English.
The main observation window is December 2025 to August 2026, covering seven harm categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons, and unauthorized model distillation.
We've split the report into 42 case units. 42 is the editorial unit count for readability, not 42 separate incidents; some units contain multiple accounts or campaigns. See the report guide and case library.
How we split case units, maintain numerical accuracy, and distinguish report facts from editorial advice is explained in methodology.
If you find errors or have corrections, please let us know via contact & corrections; facts from the original report take precedence.