Anthropic Says Criminals and State Hackers Are Weaponising Claude

The AI firm's own threat report describes Claude being used to automate break-ins, draft propaganda, and support weapons research between December 2025 and August 2026.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Anthropic disclosed that its Claude AI models were misused for cyber attacks, weapons design, propaganda and mass surveillance between December 2025 and August 2026.
  • The company groups the attackers under a new label, Generative Threat Groups (GTGs), covering state-backed teams, financially motivated criminals and commercial vendors.
  • Claude was used to automate parts of hacking campaigns, including exploiting flaws and stealing data from multiple victims.
  • Anthropic says it has banned the accounts involved and is sharing indicators with other defenders.
  • Ordinary users are not the direct target, but the report signals a shift toward AI-assisted attacks that scale faster than human-run ones.

Anthropic has published an unusually blunt admission about its own product. In a threat report covering December 2025 to August 2026, the company says criminals and state-sponsored hackers have been using its Claude models to run cyber attacks, help design weapons, churn out propaganda, and support mass surveillance.

The firm has coined a term for the groups doing this: Generative Threat Groups, or GTGs. It is Anthropic's shorthand for any organised operation, whether a government hacking unit, a for-profit crime crew, or a commercial spyware vendor, that builds AI into its workflow.

The report was picked up by The Hacker News, which flagged the automation angle: Claude was not just answering questions for attackers. It was doing chunks of the work.

What did the attackers actually use Claude for?

According to Anthropic, the hackers used Claude to automate parts of real intrusions, including finding and exploiting software flaws and then pulling data out of victim networks. That is a meaningful step up from using a chatbot to write a phishing email, which is what most earlier abuse looked like.

The misuse fell into four broad buckets:

Use case What it looked like
Cyber attacks Automating exploitation and data theft across multiple victims
Weapons design Research assistance on weapons-related topics
Propaganda Generating and shaping influence content at scale
Mass surveillance Supporting monitoring of large groups of people

Anthropic frames this as a change in tempo. When a model can plan, write and execute steps of an attack chain, one operator can hit more targets, faster, with fewer mistakes than a human typing at a keyboard.

Who is behind the Generative Threat Groups?

Anthropic says the GTGs span three overlapping worlds: nation-state intelligence services, financially motivated cybercrime groups, and commercial surveillance vendors that sell hacking tools to governments. The company has not named specific countries or crews in the material summarised so far.

That mix matters. State teams tend to care about espionage and disruption. Criminal crews want money, usually through extortion or fraud. Commercial vendors sit in between, building capability and selling it on. All three, per Anthropic, are now reaching for the same general-purpose AI.

Should ordinary people be worried?

Not in the sense that Claude is going to attack you personally. The immediate risk sits with the organisations these groups target: companies, government bodies, and the systems that hold your data. If AI helps attackers break into more of them, more quickly, the downstream effect is more breach notification letters landing in more inboxes.

A few sensible habits still cover most of the fallout:

  • Turn on multi-factor authentication, the second check (usually a code or prompt on your phone) that stops a stolen password on its own from unlocking your account.
  • Use a password manager so every site gets a different password.
  • Treat unexpected messages, even well-written ones, with suspicion. AI has closed the grammar gap that used to give phishing away.

What is Anthropic doing about it?

The company says it has banned the accounts tied to the abuse and is sharing what it found with other defenders. It is also using the report to argue that AI providers should publish this kind of detail openly, rather than quietly closing accounts and moving on.

Whether rival labs follow suit is the open question. Regulators in the United States, the United Kingdom and the European Union have all signalled interest in AI safety reporting, but none yet require a disclosure of this shape.

© 2026 Threat Vectr