Anthropic September 2026 Threat Intelligence Report: English Guide
This page is an independent English guide to Anthropic's September 2026 report (published September 10, 2026, 154 pages). The behavioral descriptions and attributions here come from that report; this site is an independent editorial project, not Anthropic's official website, and has not independently verified the real-world outcomes described in the report.
Featured report
| Detecting and countering misuse of AI: September 2026 | Anthropic · 2026-09-10 |
|---|---|
| 154 report pages | English |
| Observation window | 2025-12 to 2026-08 |
| Sources | Report page · Original report PDF |
Methodology & corrections
The original report covered on this page is Detecting and countering misuse of AI: September 2026, published by Anthropic's threat intelligence team on September 10, 2026. It runs 154 pages in English. The report's main observation window is December 2025 through August 2026; some case narratives reach back to earlier activity, and each case page notes its own time frame.
The report covers seven categories of harm: cyberattacks, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons, and unauthorized model distillation (the practice of extracting a model's capabilities without authorization to train or power other systems). The report states that the cases involved misuse of the Claude Haiku, Sonnet, and Opus models; apart from one unauthorized distillation case, none involved Claude Fable or Mythos-tier models.
The report makes clear that the included cases are not representative of typical misuse, but rather the most notable and novel examples of threat activity it has found to date. The publisher says it disrupted the activity in each case, used the information to strengthen its own defenses, and shared intelligence with authorities and industry partners where appropriate. The actors described include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda outlets, and politically motivated individuals.
This site breaks the report into 42 Chinese-language editorial units: 42 is the number of units this site split the report into for readability, not 42 separate incidents; some units themselves contain multiple accounts, organizations, or operations. The original report's Overview has been merged into this page rather than given its own page; each of the seven chapters has its own guide, keeping the original report's order and page ranges, accessible from the chapter directory below.
Key findings
- AI is embedded in real attack workflows, but the underlying techniques have not been replaced. The report frames the changes AI brings as gains in speed, scale, and depth; many intrusions still start with stolen credentials, unpatched systems, and social engineering. See the AI-assisted cyber espionage case and the cyber operations chapter guide.
- Content output volume does not equal real-world impact. The report describes a commercial influence service running roughly 70 fake news websites that produced at least 8,913 pieces of content in about 20 languages, but found no evidence of reach beyond its own network; these numbers cannot be converted into how many people were actually reached. See the cross-region commercial influence-for-hire service.
- There is a complete sample of fraud targeting individuals. The report describes more than 20 dating apps mixing AI identities with human gig workers; in a two-week window in April 2026 it identified more than 4,700 AI identities and at least 25,000 unique interacting individuals — this is the scale of interaction, not the number of confirmed victims. See the undisclosed AI identities in dating apps.
- AI services themselves are becoming targets, but the boundaries matter. The report describes fake AI reseller services stealing credentials; in another supply-chain-related case, the report explicitly states the actor did not obtain unreleased models or breach Anthropic's own systems. See the fake AI reseller services and credential theft and the hotel-system intrusion leading to an AI supply chain attack.
- Platform enforcement has clear limits. In a case involving a mass communications surveillance platform, the report says the bans disrupted the software and design activity but did not stop the already locally deployed platform — banning accounts is not the same as taking down the whole system. See the Mali mass communications surveillance platform and the surveillance chapter guide.
- In the weapons and biological domains, most of what the report observed was activity at the document, planning, and simulation stages — not the same as real-world capability already in place. For example, the drone swarm software case was mainly at the simulation and validation stage, and some funding links were self-reported by the actor and unverified. See the drone swarm software development attempt and the conventional weapons chapter guide.
- All distillation-related allegations come solely from the publisher's attribution. The report makes allegations of unauthorized distillation or data use against multiple companies and reseller networks; these are the platform's judgments, not judicial conclusions. See the unauthorized model distillation chapter guide.
Topics
- Cyber operations
p. 4–40 · 8 case units
This chapter discusses how AI changes the speed and scale of cyberattacks rather than inventing entirely new techniques. This site splits it into 6 case units.
- Influence operations
p. 41–80 · 9 case units
This chapter uses nine cases to show how fake identities, hidden sponsorship, and disguised sources make content look like independent voices.
- Surveillance operations
p. 81–110 · 8 case units
This chapter's ten units show how AI can act as both an analysis team and an engineering team, turning surveillance into routine paperwork or a local platform.
- Conventional weapons
p. 111–128 · 6 case units
This chapter's six units are split into two groups: weapons development and design, and intelligence collection and procurement. Documents and simulations are not deployment.
- Biological misuse
p. 129–138 · 4 case units
This chapter discusses intent identification under dual-use conditions: legitimate research and potential misuse can overlap thematically.
- Scams & fraud
p. 139–142 · 1 case units
This chapter has only one case, GTG-15001: the report says a dating-app network mixed undisclosed AI identities with human gig workers in the same service and charged users per message.
- Illicit model distillation
p. 143–154 · 6 case units
This chapter is the publisher's attribution report on multiple companies and reseller networks. Technical facts, allegations, and legal judgments should be read separately.
Limits of response
The sample is what the platform chose to disclose, not representative statistics. The report includes the cases the publisher found most notable and novel, not all observed misuse; one cannot derive global incidence rates, country rankings, or the overall safety of a given brand from the number of cases, their length, or how often a country is mentioned.
Platform visibility is limited. The publisher can only observe activity on its own platform; it has limited visibility into actual distribution after content leaves the platform and into real-world outcomes for victims, and most cases do not give a total loss figure or final impact.
All attribution comes from the publisher. Judgments about actor identity and motive (including qualifiers such as 'medium confidence') are Anthropic's assessments; this site consistently relays them as 'the report says' and has not independently verified them. Allegations involving specific companies are not judicial conclusions and do not represent this site's findings.
Country rankings or total losses cannot be derived from this report. The report does not provide comparable data across countries, nor does it aggregate economic losses; any claim that 'a certain country has the worst misuse' or 'the total loss is X' goes beyond the report's evidence.