Anthropic's September 10, 2026 threat-intelligence report documents new cases of malicious actors using Claude for cyber operations, espionage, scams, biological research and other harmful activity. The report is useful for more than the incidents themselves: it shows how AI misuse is shifting from simple prompts toward longer, more coordinated agent workflows.

Diagram of AI threat intelligence showing malicious prompts, agent actions, monitoring and disruption

What Anthropic reported on September 10

Anthropic says its Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. The company describes cases involving cyberattacks, espionage, surveillance, scams, biological misuse and weapons-related research.

The report is an account of misuse observed by Anthropic. It should not be read as proof that every Claude user or every AI system behaves this way. The useful signal is the type of work attackers are attempting and how much more autonomous those workflows are becoming.

Why the new report matters for AI security

Older discussions about AI misuse often focused on whether a model would answer one harmful prompt. Agentic systems create a different risk surface because a model can carry out reconnaissance, process many inputs, call tools and repeat actions.

That changes the security problem. A defender cannot only review the text returned by a model. It also has to watch the tools, credentials, network access, files and external systems around the model.

What the cyber cases show

Anthropic says threat actors used Claude to support phishing and malware-related operations, including activity linked to Russian actors targeting Ukrainian entities. The company also describes model use in other cyber campaigns where automation can compress several manual steps into one workflow.

Risk areaWhat defenders should watch
PhishingBulk message generation, targeting and repeated refinement
ReconnaissanceAutomated discovery of hosts, accounts and exposed services
MalwareCode generation, debugging and iterative changes
Data theftCredential use, collection and transfer attempts
Multi-agent workMany tasks coordinated with limited human input

AI agents are changing the threat model

The key shift is duration and coordination. A single model response can be reviewed and blocked. A tool-enabled agent can instead make one request, inspect the result, choose another action and continue.

For security teams, the control point moves from content moderation toward system design. The agent needs bounded tools, limited credentials, network controls, rate limits and logs. A model that can browse or execute code should not automatically receive the same access as a normal employee.

Why biological and weapons misuse is different

Anthropic also describes attempts to use Claude for biological research and conventional weapons-related work. These cases deserve a different review standard because the potential harm can extend beyond an ordinary fraud or software incident.

Organizations should therefore separate high-risk domains from general productivity use. Access to advanced models, external data, code execution and sensitive repositories should be reviewed according to the consequences of misuse.

What illicit model distillation tells us

The report includes attempts by other organizations to extract capabilities from Claude through large volumes of interaction. Distillation is different from an ordinary user copying an answer: the goal is to use another model's outputs at scale as training data for a competing system.

For model providers, this creates monitoring questions around unusual request patterns, repeated benchmark-like prompts, automated access and very high-volume interactions. For users building applications, it is another reason to apply rate limits and authentication controls.

How companies should prepare for AI-enabled attacks

Start by inventorying every AI-connected tool. Write down what each model can read, write, execute and send outside the organization. Then remove permissions that are not needed for the task.

Next, log meaningful actions. A useful AI security log should capture the model or agent identity, tool selected, target system, time, approval state, result state and any external side effect. The log should be useful after an incident, not just during a live session.

What to monitor around an AI agent

Model output is only one signal. Network telemetry can show unexpected destinations. Identity logs can show unusual credential use. Tool logs can reveal repeated attempts to bypass a restriction. File activity can show data collection that the text transcript does not make obvious.

Security teams should also define stop conditions. If an agent touches a system outside its allowed scope, the run should pause automatically instead of continuing while a human tries to catch up.

How this changes AI evaluation

AI safety evaluations need to treat the environment as part of the system under test. A model can behave differently when it has browser access, code execution, external data or real credentials.

That lesson is especially important after the recent series of reported AI evaluation incidents across the industry. The safer approach is to use synthetic targets where possible, isolate networks, use disposable credentials and keep strong monitoring outside the model itself.

What businesses should take from the report

The practical takeaway is not to stop using AI. It is to stop treating model access as if it were the only security decision. A strong model can be useful and still need narrow permissions.

Teams adopting agents should define the smallest useful permission set, review high-risk actions, maintain audit logs and test failure paths before connecting production systems. The report also shows why security teams need a way to see AI activity as a first-class part of their threat model.

Related ToolBoxKart guides

For agent security controls, read How to Audit AI Agent Permissions. For operational evidence, see AI Agent Audit Logs: What You Should Record. For safer evaluation boundaries, read Anthropic Claude Security Review: What the Four Incidents Show. For system architecture, use the AI Agent Architect guide.

New guides from September 12

Continue with Claude Threat Report AI Security Lessons, AI Agent Approval Policy Template, and Meta Muse Personal AI Agent Security.

Frequently asked questions

What is Anthropic's September 2026 threat report?

It is a Threat Intelligence report describing operations in which attackers or other malicious actors attempted to misuse Claude for harmful activity.

Are these incidents proof that Claude is unsafe for normal users?

No. They document specific misuse cases. The broader lesson is that advanced AI systems need controls around access, tools, credentials and monitoring.

Why are agentic systems a bigger security concern?

Agents can perform multiple steps, call tools and interact with external systems. That creates more opportunities for an attacker or an unexpected model behavior to have a real-world effect.

Sources

About Deepak Parmar

Deepak Parmar is an SEO and automation expert with 7 years of experience in SEO, AI search, GEO, and web development. He specializes in helping brands improve visibility across Google, ChatGPT, Gemini, Perplexity, and other AI search platforms.

At ToolBoxKart, Deepak writes about SEO, AI, automation, search technology, and practical digital workflows, combining hands-on technical experience with real-world research and experimentation.

LinkedIn · YouTube

Latest published posts