HomeSecurityAnthropic Threat Report September 2026: How Claude Arms Hackers

Anthropic Threat Report September 2026: How Claude Arms Hackers

Anthropic published on September 10, 2026 the most detailed cyber threat report in its history — 36,000 words documenting how malicious actors attempted to use Claude from December 2025 to August 2026. The new report makes a striking claim: artificial intelligence has so drastically reduced the gap between state-owned enterprises and individual attackers that one AI operator is now equivalent to an entire state-owned team . SecNews’ technical team analyzes the most important findings, the industry’s reactions, and what this means for Greek and European cybersecurity.

Anthropic Threat Intelligence Report September 2026 Claude AI

See also: EU Cyber ​​Resilience Act: New reporting obligations start September 11, 2026

Anthropic Threat Report: What the new report covered

Anthropic's Threat Intelligence team identified and disrupted operations in seven areas of damage, using data from the Claude Haiku, Sonnet, and Opus models:

  • Cyber-business: Targeted espionage, data extraction, malware development and vulnerability exploitation
  • Influence operations: Propaganda actions from Russia, Iran, Turkey, Gulf countries, South Asia, Africa and Europe
  • Tracking: Use of Claude by commercial spyware providers to track individuals
  • Fraud and scams: Financial incentives, bank fraud, extortion
  • Biological Abuse: Attempts to manufacture biological weapons
  • Conventional weapons development: Design and improvement of traditional weapons systems
  • Illegal distillation: Stealing knowledge from Claude models to create competing AIs

In each case, Anthropic suspended activity, strengthened its internal security measures, banned the relevant accounts, and shared information with authorities and industry partners. No malicious uses were detected in the higher-tier Claude Fable and Claude Mythos models, with the exception of one case of illegal distillation.

Vibe hacking AI Claude autonomous hacker attacks

Vibe hacking: The most worrying term in the report

The new term introduced by Anthropic and extensively analyzed by independent researchers such as Pasquale Pillitteri is vibe hacking. This is the technique where the attacker gives the model a general goal and leaves it to work autonomously:

  • AI explores the target environment
  • Writes and executes scripts on its own
  • Summarizes the findings
  • Repeats the cycle until the goal is completed
  • The human no longer types commands — he simply supervises

The phenomenon is not theoretical. According to Forrester, in a previous GTG-2002 case, a single cybercriminal used Claude Code as an active operator for attacks on 17 organizations. The new report documents that this capability has now matured into a full-fledged professional practice.

Automatic malware reconstruction AI Claude Midnight Blizzard

Russian firm: Malware that reproduces itself

One of the most striking incidents in the report concerns a suspected Midnight Blizzard operator , as documented in AlphaSignal ’s analysis . The perpetrator used an automated workflow that included phishing, persistence, command-and-control, data extraction, as well as malware detection and automatic modification :

  • AI agents detected whether malware was detected by a security product
  • They were locating the specific artifact that had been detected
  • They were automatically modifying it
  • They were rebuilding it and relocating it
  • They repeated the process until the malware was no longer detected.

The operation targeted over 20 organizations, including ministries, defense and intelligence agencies, embassies, think tanks, and defense industries. The geographic targeting focused on Ukraine, Europe, the Middle East, and shipping organizations in Asia. Microsoft named the method CaptiveCrunch in a July 2026 report.

ShinyHunters: 1 TB of stolen data in 34 hours

The report also documents impressive activity from affiliates of the notorious ransomware group ShinyHunters (GTG-50014), known for pay-or-leak attacks. A French-speaking operator with the aliases MeowSHA, frkoo, and blazespider was operating an automated attack pipeline with 10 AWS EC2 workers:

  • It downloaded 1.8 million Android APKs
  • He decompiled
  • He was looking for embedded secrets with the TruffleHog tool
  • He sent the findings on Telegram
  • He classified them into over 100 types of sources

The impact of the attacks was devastating: a technology provider lost over 1 terabyte of data and millions of payment-card records, an airline lost tens of millions of passenger records, and at a SaaS provider, the attackers gained access to data from approximately 200 downstream customer organizations with 2,100 Azure AD token sets — in just 34 hours. Analysis by Halcyon.ai notes that in a previous similar case, an attacker without programming skills managed to create ransomware with the help of Claude.

See also: NSK cyberattack: Hackers removed all data of the State Legal Council

Anthropic Threat Report: Chinese student lab activities

Of particular interest is the GTG-10007, which involved a group of Chinese-speaking operators, possibly from Changsha, Hunan Province. Two members were identified as undergraduate students at a computer and communications engineering school, while one had interned at Sangfor and was interviewing for an offensive cybersecurity role at QiAnXin. The targets were approximately 50 organizations in education, retail, energy, technology, healthcare, and government agencies.

Most worryingly, the perpetrator developed what the report describes as a zero-day exploit foundry. An automated vulnerability discovery workflow in which firmware and binaries were loaded into a decompiler, thousands of disassembly calls were made, vulnerability hypotheses were generated, and exploits were written and tested iteratively. One workflow alone yielded over 12 potential zero-day vulnerabilities in a month.

Influencer marketing: 8,913 articles in 20 languages

Anthropic examined nine cases of influence operations from Russia, Iran, Turkey, the Gulf States, South Asia, Africa and Europe, targeting audiences across six continents. Two cases stand out:

AI supply chain attacks API keys prompt injection Claude
  • GTG-04001 (Central African Republic): A Russian-speaking operator in Bangui operated a production base for Russian state-aligned propaganda via Radio Lengo Songo (98.9 FM), in coordination with RT, Sputnik Afrique, and TASS. He used Claude to draft contracts that required loyalty to the country's President "and to Russia and its contingent."
  • GTG-54002 (French company LKM Company): Influence-as-a-service commercial enterprise with 70 fake news websites, 70 corresponding X/Twitter accounts and over 250 inauthentic comment accounts. Published 8,913 articles in 20 languages ​​targeting the US, Brazil, France and DR Congo, with no fixed ideology — political direction changed depending on the client

Critical attack on AI supply chain: Claude as a tool and as a target

Particularly notable is the case of GTG-50020, a Russian-speaking actor who evolved from attacks on hotel booking platforms to targeted attacks on AI vendors. He used prompt injection in an AI vendor evaluation sandbox, which delivered production API keys from multiple providers. In just four days, he targeted approximately 30 AI companies.

Its primary goal: accessing a Claude model before it was released. It attempted more than a dozen different routes, but all failed. Anthropic clarified that its own systems were not compromised — the stolen API keys came from its customer environments. The report also documents case GTG-50021, where a Russian-Ukrainian group sold cheap “Claude access” that actually pushed traffic to another model and stole buyers’ credentials.

How did the industry react to the report?

Reactions from the industry are varied. Positive reviews from:

  • Cellcog.ai: "Anthropic's most comprehensive report to date" with detailed case studies and truly critical findings on the evolution of AI-driven attacks
  • Clauding.de: Good structure, clear categorization into seven areas of damage and responsible disclosure

At the same time, there are skeptical voices. Regulayer noted of the previous report that “the claim of 80-90% autonomy and the attribution to a state group is based entirely on Anthropic’s self-publicity, without independent verification.” The BBC covered similar skepticism in its coverage of the GTG-1002 case in November 2025, where researchers questioned the full accuracy of the claims.

See also: AI terms you need to know: Complete Artificial Intelligence Glossary 2026

What does it mean for Greek cybersecurity?

The SecNews editorial team highlights four immediate consequences for Greek businesses and public bodies:

  • The attack threshold has dropped: A single attacker with access to an AI model can now execute an operation that previously required a state-level team. Greek SMEs are becoming targets of attacks as serious as large organizations
  • Traditional signature-based systems are not enough: When malware automatically re-engineers itself until it is undetectable, signature-based EDR/XDR solutions become ineffective. Behavioral and anomaly-based detection is needed
  • AI credentials are the new target for resale: Stolen AI model API keys have a dual value — they are resold as loot but also enable attacks at the victim’s expense and cover under their identity. Greek companies that integrate AI APIs should handle their keys with the same level of care as root passwords
  • Procurement of AI-based products requires a different assessment: The EU Cyber ​​Resilience Act, NIS 2, Law 5086/2024 and directly the AI ​​Act create a network of obligations for secure procurement. CISOs of Greek companies must integrate AI supply chain security into supplier assessments

The future of AI-driven attacks

The September 2026 Anthropic Threat Report is, beyond a technical document, a statement from the industry: AI-driven attacks are not a theoretical risk, they are an everyday reality. The main trends to watch in the coming months:

  • Expansion of vibe hacking to even more categories of criminals without technical training
  • Maturation of AI agent swarms with lead agents and parallel execution subprocesses
  • Integrating AI across the entire attack lifecycle, from recognition to exit and redemption
  • Increase in attacks on the AI ​​supply chain: theft of API keys, prompt injection into corporate workflows, breach of local AI gateways
  • More complex influence operations that will be increasingly difficult to distinguish from authentic content

Anthropic closes its report with a clear position: responsible disclosure, enhanced protections, and sharing information with the security community is the only way to maintain balance. The company’s official statement on X (formerly Twitter). The question remains whether other major AI providers will follow suit with similar transparency — or whether market competition will lead to tacit tolerance for malicious uses.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS