Anthropic has disclosed that its Claude AI models were leveraged by cyber actors spanning state-sponsored, commercial, and criminal backgrounds between December 2025 and August 2026 to automate exploitation, reconnaissance, and mass data theft. These Generative Threat Groups (GTGs), as internally defined by the company, have blurred the technical and resource divisions that once separated major nation-state actors from smaller, opportunistic digital adversaries.
Who Are the Threat Actors?
The timeline of misuse includes clusters like GTG-20006—a group linked to Russia’s Midnight Blizzard (also known as APT29 or Cozy Bear)—that used Claude not just for malware blueprinting but full workflows. These steps included reconnaissance, vulnerability exploitation, and data exfiltration with minimal human supervision.
Other groups documented include:
- GTG-50014: A French-speaking affiliate of ShinyHunters. Operated a credential-harvesting network via ten EC2 instances which mass-downloaded nearly 1.8 million Android APKs to scan for secrets with tools like TruffleHog. Findings were pushed into a Telegram group.
- GTG-10007: Based in China’s Hunan province. Made up of university undergraduates. Used Claude to try penetrating production systems, probing foreign-government networks across the Middle East, Europe, and Southeast Asia, developing unpublished endpoint-security exploits, and gathering open-source intelligence aligned with Beijing’s priorities.
- GTG-50021 & GTG-50020: One ran a fake resale front for Claude that harvested credentials from users, the other primarily targeted AI vendors’ API keys and pre-release models. The latter group attempted to breach around 30 providers in just four days.
- GTG-50029: A French-speaking threat actor who exploited flaws like WordPress race conditions and exposed endpoints to breach political organizations and infiltrate development platforms. Also built ‘‘fafsearch,’’ a doxxing tool to match breached data across sources.
Disinformation & Surveillance Campaigns
Claude’s misuse wasn’t limited to intrusions and malware: several GTGs produced content at scale to manipulate public opinion and monitor dissident or minority populations. These influence operations ranged from fake news site networks rewriting political stories, to profile-building across phone, social, and geolocation data.
Examples include operations linked to China targeting Uyghur diaspora activist figures, Iranian groups drafting briefings from social media content, a Bangladesh-based network pushing partisan Bengali content, and Kenya- and Iran-oriented platforms surveilling minorities or political opposition. A complex surveillance operation even created a mobile network monitoring system covering tens of millions of SIM cards.
Anthropic’s Findings & Mitigation
Anthropic mapped over 150 pages of investigations detailing misuses that ranged from war-container-level threats—like guided weapons specification drafting and drone swarm targeting—to influence operations and credential theft.
The firm says it disrupted many schemes before they gained meaningful engagement. Notably, influence campaigns using Claude as automated content generators were curtailed. Still, the company warns that many operations had already been scaling below detection, harnessing Claude conversationally in some phases, and with multi-agent autonomous systems in others.
Anthropic’s internal assessment stresses that model providers are increasingly positioned to see threat behavior more directly than many governmental or international bodies. Public sharing of such intelligence is framed as essential toward establishing norms, safeguards, and regulatory guardrails for large AI systems.
Why This Matters
This report crystallizes a troubling shift: AI is no longer just a tool for advanced actors—it’s empowering smaller groups to conduct operations once considered state-level. Vulnerability development, exploitation pipelines, surveillance, and disinformation are being automated. For defenders, this raises key questions about detection ahead of scale, attribution when multiple languages and proxies are used, and whether platforms can build robust monitoring without sacrificing privacy. Going forward, expect regulatory pressure to mount, more mandatory disclosure from AI vendors, and possibly industry-wide audits of how models are accessed, used, and misused.