
Image: METAL
Summary
- Anthropic says it found and disrupted attempts to misuse Claude between December 2025 and August 2026, and published the case studies. The report spans seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons, and distillation.
- A crew attributed to Russian state-linked espionage compromised at least three hotel guest WiFi vendors, hijacked DNS to infect guests' devices, and pulled more than 300,000 national identity records from a North African government body.
- Much of the AI compute behind the attacks came from stolen customer API keys. One group hit roughly thirty AI companies in about four days, and every attempt to reach a pre-release Claude model failed, the company said.
Connecting to the WiFi in a hotel lobby was enough to get a device infected. According to the threat intelligence report Anthropic released, a crew attributed to Russian state-linked espionage first compromised at least three vendors that operate guest WiFi for hotels. It then rewrote DNS records to point at its own servers and pushed Windows, Android, and iOS malware onto the devices of guests who connected. The people it was after were Ukrainian government officials and staff at drone manufacturers.
That case is one of several in the report Anthropic published. The company said it identified and disrupted attempts to misuse its model Claude over the eight months from December 2025 through August 2026, sorting them into seven areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. The models involved were Haiku, Sonnet, and Opus; apart from a single distillation case, no misuse was found on Fable or Mythos-class models, the report said.
The Russian crew is designated GTG-20006 in the report. The company wrote that its attribution is consistent with public reporting linking the actor to Midnight Blizzard, and said one operator is a Russian speaker using the handle JackPoterz. The group targeted more than twenty organizations, concentrated in Ukrainian government bodies, European diplomatic missions, and defense-industrial firms. From one North African government technology authority it took an entire credential database: more than 300,000 national identity records and commercial registry data for more than half a million companies.
What this crew demonstrated is less about scale than speed. When deployed malware was flagged by a security product, monitoring AI agents rewrote and rebuilt the code themselves, repeating until it stopped being detected. The report treats this as a reversal of the cost structure. The company wrote that capable adversaries can now "close the loop," bypassing traditional security detections faster than defenders can develop and deploy them.
The numbers are larger on the financially motivated side. Operators suspected of being ShinyHunters affiliates ran a fleet of ten cloud workers to download and decompile 1.8 million Android apps, scraping the credentials baked into their code. More than a terabyte of data left one technology provider, and at an airline the attackers reached systems holding tens of millions of passenger records. At an energy company, the operators claimed they could remotely adjust the charging current of electric-vehicle chargers installed in customers' homes.
The clock makes it clearer still. After breaching one software-as-a-service provider, they pulled data belonging to roughly 200 of its downstream customers, and in about 34 hours swept up more than 2,100 sets of authentication tokens spanning over 40 corporate tenants. AI agents performed nearly all of that work, the company wrote. In another case, a single stolen developer token grew into full administrative control of a victim's cloud environment in roughly three hours.
The face of the attacker has changed too. GTG-10007, whose operators speak Chinese, appears to be based in Changsha in Hunan province, and two of them were identified as undergraduates in a School of Computer and Communication Engineering at a Hunan university. One had interned at the Chinese security company Sangfor and was interviewing for an offensive-operations role at another, QiAnXin. Their automated vulnerability research produced more than a dozen possible zero-day findings against network appliances in a single month, and a fleet of thirteen standing collection agents ran on a schedule.
Here is the most uncomfortable part of the report. Much of the AI compute behind these attacks came not from the attackers' own accounts but from other people's. One Russian-speaking group injected instructions into an AI vendor's automated evaluation sandbox and made it hand over the production API keys it held for several providers, then used the same infrastructure to attack roughly thirty AI companies in about four days. On that case the company drew a line, writing that the keys involved were all customers' keys stolen from customers' environments, and that the actor never compromised Anthropic's own systems.
What that same group pursued across more than a dozen avenues was access to a pre-release Claude model, and the company said every path failed. As the keys themselves became merchandise, fake resellers appeared. A Russian- and Ukrainian-speaking group using the handle kl1zy drew customers with the promise of cheap Claude access, while quietly proxying their traffic to a different model and installing a credential harvester that stole their Anthropic account details and sold them on to other resellers.
METAL read the report in full, and the sentence the company keeps returning to is that sophistication is no longer a signal. Multi-victim campaigns that once would have required several skilled operators were each carried out alone: by one activist working from stolen keys, by scattered criminals, and by a state espionage operator. METAL reported earlier on a Taiwanese security firm's finding that attacks by Chinese state-linked groups more than doubled after they adopted AI, and this report fills in, case by case, the shape that increase takes.
The company also admits a limit. The report says sophisticated and persistent threat actors continuously test its safeguards and try to circumvent them, and states plainly that the cases collected here are not typical misuse but the most notable and novel activity identified so far. Saying they are not typical is also a way of saying that what was caught is not all there is.
In short, Anthropic has put on the record how far its own model was pushed into harm, with cases and indicators attached. What AI removed was not the tooling for an attack but the people and the hours it used to take, and the bill for the compute landed on the companies whose keys were stolen. What is left is not a technical problem but a question of where responsibility sits. The moment one API key leaks, that company becomes both the victim of its own breach and the funding line for someone else's attack, and contracts and regulation have not caught up with that arrangement.





Comments