Here are all the case articles we created for this report. Each unit preserves the original report's page numbers, numerical claims, and unknowns.
42 is the number of editorial units: some units contain multiple operations, some combine two source IDs into one article. It should not be understood as '42 independent cases' or a global statistic.
According to Anthropic's September 2026 report, GTG-20006 is a cyber espionage actor who uses AI to automate operations and gain speed. Anthropic says its attribution is consistent with public reporting linking the actor to Midnight Blizzard. The actor used a custom toolkit including two types of Windows implants, a mobile exploitation suite, a credential stealer targeting browser password vaults, a phishing platform designed to impersonate priority targets such as government organizations, and a management console for controlling compromised accounts. The report observed that GTG-20006 automated most of its operations — from development, infrastructure acquisition, phishing, command-and-control persistence, to data exfiltration — through customized AI-driven workflows.
According to Anthropic's report, multiple opportunistic intrusion clusters suspected of being linked to the ShinyHunters group used AI to enhance their criminal activity. These actors broadly scanned unpatched internet-facing systems, rummaged through public containers, code repositories, mobile apps, and more for credentials, tokens, and API keys, then went straight for databases to steal customer data after gaining access, and extorted victims by threatening to publish or sell the data. The report says AI agents did most of the work, with one case going from a stolen token to full control of a victim's cloud environment in about 3 hours. The report also makes clear: Anthropic's own systems were not breached by this actor.
According to an Anthropic report, a group of Chinese-speaking operators assessed to be likely based in Changsha, Hunan, China, used Claude as the engineering and orchestration layer for a coordinated attack campaign. Multiple workflows ran in parallel: intrusions into production systems, reconnaissance of foreign government networks, ongoing vulnerability research and exploit development against mainstream endpoint security products, malware development, and operation of an unattended intelligence-collection platform. The targets were roughly 50 organizations. Attribution information such as the operators' location comes from the report's assessment; their vulnerability findings were validated only in the actors' own experimental environments.
According to Anthropic's report, the AI supply chain has become a target, loot, and source of attack compute for malicious actors. AI access in the form of stolen API keys, session tokens, and devices is increasingly the sole objective of multiple criminal groups. GTG-50021 is a fake AI reseller service operated by a Russian- and Ukrainian-speaking actor. Customers thought they were buying discounted Claude access, but their traffic was silently routed to other models; the reseller tool also installed a credential collector on the device, reselling account credentials to other proxy networks.
According to Anthropic's report, GTG-50020 is a Russian-speaking, financially motivated actor that historically targeted hotel booking and fintech platforms. In one intrusion, they exfiltrated about 26 GB of data from a victim and attempted to obtain $1.5 to $2.5 million through ransom (or by selling the data on dark web forums). They then pivoted the same techniques toward the AI industry: by injecting malicious instructions into an AI vendor's automated evaluation sandbox, they made the sandbox hand over the credentials it held—including production AI API keys for multiple providers held by that vendor. The report makes clear: the actor never obtained access to unreleased Claude models, and Anthropic's own systems were not breached.
According to Anthropic's report, in spring 2026 a French-speaking actor used Claude to target European political parties, media, think tanks, and the software services they use. The report tracked 42 target entities, of which at least 14 were internally accessed, with an estimated 12 to 26 GB of data stolen. This is an example of one person using AI to scale intrusion and data correlation capabilities; this page does not provide any personally identifiable data.
According to the report, an Iran-linked threat actor used Claude to collect and analyze publicly available data to develop targeting recommendations against U.S. Navy forces in the region. The actor used Claude to write targeting handbooks, identifying and tracking naval positions based on open-source information. The same account also developed enterprise software for Iranian state systems, including designing a large-scale domestic surveillance platform combining automatic license plate recognition and mobile device identifier interception. This page does not publish any target coordinates or exploitation details.
According to the report, an Iranian threat actor used 16 free Claude.ai accounts across 16 single-operator organizations to develop malware, delivery pipelines, and phishing portals targeting domestic Iranian users. The delivery pages were designed to serve malicious content only to visitors with IP addresses from Iran, themed around censorship-circumvention tools and fabricated Persian-language news brands. The actor used Claude to develop the SECOMS64 modular Windows implant, including a keylogger, screenshot capture, Chrome credential extraction, and more. This page does not publish any malware code or phishing links.
According to an Anthropic report, a Russian-language actor based in Bangui, the capital of the Central African Republic, used Claude to produce daily content for a local radio station, packaging pro-Russian narratives as local programming and designing a distribution chain that connects to national broadcast channels. The report links this operation to Russian state-aligned foreign information manipulation and rates it as Category 4 on the Breakout Scale. All attribution and assessment wording comes from the report.
According to Anthropic's report, a network disguised as 'independent local newsrooms' used Claude to mass-produce and rewrite political content: about 70 fake news websites, at least 8,913 articles, about 20 languages, plus 70 associated X accounts and over 250 fake comment accounts for amplification. But the report also emphasizes: most content had almost no real audience engagement, and no evidence of spread beyond its own network was found — output volume is not the same as influence. The report traced the network to a French digital advertising company, could not confirm the paying clients, and found no evidence of any government direction.
According to the report, a commercial platform disguised as a 'defensive cyber intelligence and counter-disinformation tool' actually primarily offered election manipulation capabilities targeting Malaysia: about 1,000 fake X accounts, a fake news website, and multiple fabricated 'intelligence dossiers.' The report's investigation found a clear link to an Istanbul-based technology company. The report assessed it as Tier 2 on the Breakout Scale, with no evidence of spread beyond real communities; this case does not show that any election result was affected.
According to the report, four individuals used Claude as an editorial desk, feeding finished copy directly into the production pipeline of Russian state media. Anthropic assesses with high confidence that this content was ultimately published through channels including Sputnik, RIA Novosti, and RT. The reach the report could verify ranged from posts with around 2,000 views to broadcast text; it cannot determine what share of these channels' total output passed through Claude.
According to the report, three accounts linked to Iranian state propaganda organizations used Claude to plan so-called "soft war" or "cognitive warfare" projects: campaign plans, persona systems, and target databases. The report links each of the three accounts to a different organization. These materials are primarily planning and preparation and should not be presented as fully executed.
According to the report, an operator based in Gaibandha District, Bangladesh, rotated 29 Claude accounts to mass-produce fake Bengali news, with content favoring the Awami League and attacking its opponents. Internal communications stated that "no one knows these news are fake." The report cites output of at least 1,500 headlines and 300 fabricated narratives; it also states there is no evidence that the party itself directed or funded this network.
According to the report, an influence operation targeting audiences in and outside Iran used a shared AI agent to impersonate a real activist: it read about 8,400 of their Telegram posts to mimic their writing style, then held real-time political conversations with their contacts. As far as the report knows, these contacts did not know they were speaking to an AI-assisted account. This page does not list any individuals or contact details.
According to the report, one operator used Claude to generate batches of exactly 50 Kenyan political posts, with explicit instructions to make them look like spontaneous grassroots comments. The report found no evidence of government involvement and assessed that the operation stayed within its fake-account network without reaching real users. Once again, output volume is not the same as influence.
According to the report, one operator used Claude to maintain an AI persona named 'Deadshot' and embedded a unified transatlantic and regional mission in its system prompt. The report links it with high confidence to UAE officials. The operation included about 300 fake influencer accounts, a front NGO impersonating a real Swiss organization, and preparation of materials targeting UN mechanisms. All links below are the report's assessments.
According to the report, a suspected commercial intelligence firm used Claude to build a prototype surveillance platform that batch-analyzed public posts by social media users in Iran and the Gulf region, inferred their location, group affiliation, and political leanings, and generated intelligence briefings in the style of government documents. The report discovered the operation during its pilot phase and found no evidence it was used against real targets.
According to the report, an operation aligned with the Chinese government's collection direction used Claude to track, profile, and attempt to recruit members of Uyghur communities in Syria. The operator did not speak Arabic, and the model provided dialect drafting, real-time translation, and task quality checks. The report assesses with low confidence that the operator was a contractor rather than a direct national security organ. The ethnic label is the target background described by the report, not an indication that the group itself is at risk.
According to the report, a group of accounts aligned with the Chinese government's direction used Claude as an analysis team to generate Chinese-language profiles of religious leaders and diaspora figures across Asia, following internal templates. Targets included Catholic, Tibetan Buddhist, Falun Gong, and Taiwanese Christian communities. This page only discusses group-level privacy risks and does not include any individual names or location details.
According to the report, a group of accounts was used to carry out three operations: a local internet police public-opinion pipeline, a police academy student's 'stability maintenance' report, and a local state security department's daily briefing. Targets ranged from domestic petitioners to overseas democrats and human rights organizations. These are three operations within one article unit; 'one case' should not be understood as 'one incident.'
According to the report, an operation within China used Claude as an automated 'public opinion monitoring' and intelligence analysis system. The actor instructed Claude to generate government briefings listing dissidents, activists, ethnic minorities, Chinese diaspora communities, and foreign media as threats to political stability. The report assesses with medium confidence that the operation was carried out by a contractor working for government clients, rather than by a state organ acting directly.
According to the report, two units linked to Iranian paramilitary and domestic security agencies used 16 Claude accounts to build surveillance systems and a malicious Firefox browser extension. A seven-department organization claimed to maintain a database of Iranian national identity records and monitored and profiled 6,388 Iranians over one year. Another provincial unit based in Qom developed a malicious Firefox extension called "al-Najm al-thāqib" to mass-collect user identities from major social network platforms. This page does not publish any surveillance logic or extension code.
According to the report, an independent consultant possibly based in Bamako used Claude to build a national surveillance platform called "Lakana 360" for Mali's national intelligence agency, the "Agence Nationale de la Sécurité" (ANSE), monitoring about 25 million SIM cards across the country's three national mobile operators. The platform was designed to circumvent Malian law's requirement for a court order to disclose certain surveillance records. This page does not publish any surveillance logic or data fields.
According to the report, an Iran-linked threat actor used Claude to build an automated open-source intelligence identity profiling tool targeting Israeli government and non-government individuals and Jewish diaspora organizations. The actor also used Claude to modify the open-source LSASS credential dumper NanoDump and build a custom C++ obfuscation/build pipeline to obfuscate malware samples and hinder analysis.
Surveillance operationsData analysisSoftware development
According to the report, a threat actor group in northern Yemen ran three weapons development programs: a guided rocket with terminal homing using commodity phone-grade flight computers, a multistage ballistic missile claiming a range of over 2,000 km, and the 'R2000' series of multi-variant missiles including a hypersonic glide vehicle variant. The actors used Claude Code in place of human software engineers to develop guidance, navigation, and control (GNC) software. The actors conducted a guided rocket test launch, which appears to have failed. This page does not publish any weapons software code or parameters.
According to the report, a China-linked actor used Claude to advance three parallel document workstreams for an anti-torpedo weapons system: a Chinese-language specification, a technical proposal of over 200 pages, and a comparison briefing against US programs based on public sources. The actor claimed to be a US defense OEM; the report assesses it to be linked to China's defense industry. This page distinguishes document generation from actual weapons deployment and does not publish any technical specifications.
According to the report, a freelancer likely based in Russia used Claude Code to write suicide drone swarm software called DronDoc / Serafim, and tested it in software-in-the-loop simulation, rented compute resources, and development boards. The report observed real hardware-in-the-loop testing, but overall the activity remained focused on simulation and development. Some funding connections are the actor's own unverified claims. This cannot be presented as established operational capability.
According to the report, a Chinese actor used Claude's chat, coding, and agent work tools to design, build, and iterate on a Chinese-language electronic warfare software suite of about 16 modules, used to detect, jam, or spoof adversary radars and communications, and to suppress adversary air defense systems. The software analyzes adversary radars, air defense missile sites, command posts, and communication nodes, calculates their detection coverage, assesses jamming effectiveness, ranks targets by value and vulnerability, and determines how to best allocate jamming sorties. This page does not publish any target coordinates or software logic.
According to the report, an actor based in Russia used Claude to research and draft procurement documents for goods that can be used for both civilian and military purposes, potentially for Russian government and defense industry clients. At the center of the operation was a person claiming to be a procurement manager at a Moscow design bureau. The procurement involved German-made three-axis fluxgate magnetometers, thousands of space-grade photovoltaic wafers, aviation crew oxygen systems, and more. This page does not publish any supplier information or procurement details.
According to the report, a threat actor based in China used Claude to collect open-source intelligence on advanced directed energy weapons, edit intelligence products, and draft Chinese-language briefings. The actor claimed to be a defense intelligence writer and internal publication editor, leading a three-person team. The actor attempted to identify a specific microwave-generating device and its supplier through iterative probability-weighted attribution, with the goal of reverse-engineering the weapon, developing countermeasures, and benchmarking it against Chinese systems. This page does not publish any weapons parameters or supply chain details.
According to Anthropic's September 2026 report, a funding application involving gain-of-function research was blocked by a biosecurity classifier, and the investigation uncovered a resale platform that bypassed regional blocks and served dozens of life-sciences researchers. The report shows the platform's operator rebuilt access within days of the takedown. The report withholds the names of institutions and countries and does not assert that the researchers intended harm.
Biological misuseContent generationSoftware development
According to the report, in May 2026 a researcher outside the United States was found using Claude in research related to highly pathogenic avian influenza, focusing on the virus's adaptation to mammals and the mechanisms of severe disease. The relevant influenza variants have pandemic potential and are themselves legitimate subjects of scientific research. The report notes the work was at an early planning stage, and the protections of stronger models limited the help that could be provided. The report does not indicate that a biological weapon was completed.
According to the report, an account wrote an orthopoxvirus research funding application for a state-linked infectious disease laboratory. Orthopoxviruses include the smallpox pathogen variola virus and Mpox, which caused a global outbreak in 2022. The account was a resale relay serving more than a dozen unrelated clients, exchanging tens of thousands of messages with Claude over a few days. The research is dual-use in nature, and Claude provided information, so it was not blocked by the classifier.
According to the report, two researchers used Claude to study venoms and toxins — compounds that can be developed into painkillers and antidepressants, but could also be used as incapacitating agents. The research had clear therapeutic goals, but the output included scaffolds for both therapeutic and paralytic targets. The report notes that classifiers cannot simultaneously enable beneficial use and prevent harm because user intent cannot be reliably identified in high-tech dual-use fields.
According to an Anthropic report, a Chinese app studio used Claude to build a network of more than 20 dating apps and power AI virtual identities that conversed with users — even though its services were advertised as entirely human-run. In a two-week window in April 2026, the report found more than 4,700 distinct AI virtual identities interacting with at least 25,000 unique individuals. The studio also recruited real people to mix into the same matching feed as the bots, mainly for authenticity checks. The ratio of AI to humans was roughly 3:1.
According to Anthropic's September 2026 report, an operator linked to Alibaba is alleged to have launched the largest distillation attack the report has measured, targeting the chain-of-thought reasoning records of Claude Opus 4.6 and 4.7. The report says the data was used to train the Qwen series of models. All attribution and figures come from the report's unilateral allegations; the companies involved have not confirmed them on this site.
Illicit model distillationContent generationSoftware development
According to the Anthropic report, Moonshot (the developer of the Kimi models) silently forwarded customer requests to Claude and then displayed Claude's responses to users, who thought they were using Kimi. In one ten-day window, nearly 300,000 customer requests were forwarded, the vast majority to Opus; the proxy network had 5,380 fake accounts. The report did not confirm whether users were aware. All of the above are the publisher's allegations, not this site's independent findings, and not a judicial conclusion.
According to the Anthropic report, DeepSeek also deployed a strategy similar to Moonshot's: building a CoT extraction pipeline, using the same cross-session replay attack to extract Claude's chain-of-thought records, and silently forwarding conversations to Claude without notifying customers. The report also says DeepSeek routed requests from users of third-party coding tools to Claude Opus, including sensitive data from Chinese tech companies, Russian defense agencies, and Chinese public security surveillance systems. All of the above are the publisher's allegations, not this site's independent findings.
According to an Anthropic report, Zhipu (overseas brand Z.ai) ran a chain-of-thought extraction pipeline against Claude, feeding captured Claude reasoning traces back into Claude for cleaning and using them to train its GLM model. The report states that over 10 days, Zhipu ran the extraction pipeline against Opus 4.8 through 273 fraudulent accounts, recording 770,000 exchanges. The report also alleges Zhipu distilled the cyber capabilities of leading US frontier models. All of the above are allegations by the publisher and have not been independently verified by this site.
Illicit model distillationContent generationSoftware development
According to an Anthropic report, Xiaomi replayed user conversations and programming sessions from its own MiMo model to Claude, often routed through third-party programming tools. The investigation did not show that Xiaomi used Claude's responses to directly serve its users; rather, it saved conversations between Xiaomi customers and its own model. Many sessions were routed through third-party routing services commonly used by US and European users. This case differs from the Moonshot / DeepSeek cases of 'substituting its own model's answers': Xiaomi did not use Claude responses to directly serve users, but saved the conversations.
According to an Anthropic report, the proliferation of proxy services has created a secondary market through which labs can buy or obtain records of users' exchanges with Claude. SenseTime's distillation pipeline included user-Claude exchange records purchased from third-party data vendors. MiniMax built a proxy network service through shell companies that only provided access to Anthropic and OpenAI models, not any Chinese models, suggesting its purpose was to collect users' exchanges with US frontier models to train its own model. All of the above are allegations by the publisher and have not been independently verified by this site.
Illicit model distillationSoftware developmentData analysis