Between December 2025 and August 2026, Anthropic said cybercriminals and state-sponsored hackers used its Claude models "for cyber attacks, weapons design, propaganda, and mass surveillance." The company's 154-page report catalogs dozens of campaigns—organized into what Anthropic calls Generative Threat Groups (GTGs)—and describes both human-supervised workflows and fully autonomous, multi-agent frameworks that executed reconnaissance, exploitation, and data exfiltration across many victims.
Anthropic's GTG taxonomy and central warning
Anthropic grouped activity into Generative Threat Groups (GTGs) spanning "state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals." The company warned that "the cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well‑resourced, state‑sponsored operations from individual operators." Anthropic said these abuses ranged from conversational assistance in malware creation to multi-agent frameworks running hours- or days‑long campaigns against multiple victims.
High-profile intrusions: GTG-20006, GTG-50014, GTG-10007
Anthropic highlighted a Russian state‑sponsored workflow it labeled GTG‑20006, which it said "aligns with broader reporting linking the cluster to Midnight Blizzard (aka APT29 and Cozy Bear)." The company also described GTG‑50014, a French‑speaking operator and suspected ShinyHunters affiliate that ran a distributed credential‑harvesting pipeline using 10 AWS EC2 workers to mass‑download 1.8 million distinct Android APKs from multiple app stores, scan them for hard‑coded secrets with TruffleHog, and forward verified findings to a Telegram group.
Another major cluster, GTG‑10007, was described as a Chinese‑speaking operator likely based in Hunan province whose members included undergraduate students. Anthropic said GTG‑10007 used Claude to attempt intrusions against production systems, reconnaissance of foreign‑government networks across the Middle East, Europe, and Southeast Asia, vulnerability research and exploit development against major endpoint‑security products, and an intelligence‑collection platform for bulk‑harvesting open‑source material. The group targeted about 50 organizations across education, retail, energy, technology, healthcare, finance, manufacturing, and government sectors, and "maintained an autonomous vulnerability research program to produce working exploits."

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageSupply‑chain theft, credential siphons, and model‑key theft (GTG‑50021, GTG‑50020, GTG‑50029)
Anthropic documented financially motivated and supply‑chain operations that shifted focus to the AI ecosystem itself. GTG‑50021 ran a fraudulent AI reseller operation: customers were sold cheap Claude access while their traffic was proxied to another model, and the scheme installed a credential harvester to capture Anthropic account credentials for resale. GTG‑50020, a Russian‑speaking actor, moved from targeting hotel booking and fintech platforms to stealing model provider API keys and attempting to access pre‑release models, targeting an estimated 30 AI vendors in a four‑day window.
GTG‑50029, a single French‑speaking operator, used Claude to target European political parties, media, think‑tanks, and their SaaS providers, exploiting a previously undocumented WordPress re‑installation race condition to create rogue administrator accounts and abusing an exposed search endpoint to breach a political campaign management platform. Anthropic said this actor deployed web shells, a browser exploitation C2 framework, and a doxxing platform named "fafsearch" to cross‑reference breach dumps against exfiltrated data.
Influence, surveillance, and state‑aligned campaigns (select GTGs)
Anthropic said it identified and took down a number of influence operations and surveillance efforts that used Claude as a "sub‑editor or content creator." Examples include a commercial "influence‑as‑a‑service" operation traced to LKM Company in France (GTG‑54002) that mass‑produced content across some 70 fabricated news websites, and GTG‑54006, a sustained automated network using 29 Claude accounts to generate Bengali‑language news and promote Bangladesh's Awami League.
The report also cataloged China‑linked clusters: GTG‑14010, which used Claude to convert bulk conversations from over 100 monitored WhatsApp groups and dozens of Telegram channels into structured Chinese‑language data for targeting Uyghurs and armed formations in Syria; and GTG‑14022, a China‑based "public opinion monitoring" operation that prompted Claude to produce government briefings labeling dissidents and diaspora communities as threats.
Anthropic described Iran‑nexus and Mali cases as well: GTG‑30005 developed targeting recommendations against U.S. naval forces and components of a domestic mass‑surveillance platform, GTG‑30004 built a profiling service targeting Israeli and Jewish diaspora organizations, and GTG‑50027 used Claude to design Lakana 360, a national mass‑interception and surveillance platform for Mali that Anthropic said could monitor about 25 million SIM cards and collect call records, text messages, and voice calls.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams should note Anthropic's finding that activities ranged from human‑guided prompts to "autonomous" multi‑agent exploitation; defenders will need to detect not only novel payloads but coordinated, long‑running automation across cloud instances and SaaS supply chains.
- Policymakers and regulators are presented with a new form of visibility: Anthropic said "providers will continue to acquire threat‑relevant visibility into real‑world use that even governments and intergovernmental organizations lack," suggesting technical controls and disclosure policies for model misuse may become a governance focus.
- Affected enterprises and procurement leaders must reckon with attackers stealing provider API keys and compromising SaaS vendors, and with adversaries using automated tools to find and exploit race conditions and exposed endpoints in widely deployed platforms such as WordPress and campaign management systems.
Anthropic's catalogue is specific and sprawling: credential harvesters, doxxing platforms, model‑key theft, autonomous exploit frameworks, and nation‑scale interception tools. As the company put it, it hopes "sharing these early insights with the public helps inform governments, the industry, and the general public on the nature of these risks, and the safeguards that are necessary for ensuring the safe deployment of AI models." Whether those safeguards will keep pace with the range of GTGs Anthropic describes is the open operational question at the center of the report.




