Source · DiggingBeagle record
Countering misuse of AI: September 2026
Anthropic threat-intelligence report covering December 2025 through August 2026, including agentic espionage, criminal targeting of AI infrastructure, and hacktivist operations.
- Published
- Sep 10, 2026
- Accessed
- Sep 14, 2026
- Publisher
- Anthropic
- Source type
- primary
- Version
- 2026-09-10
- Rights
- Public web source; citation and short excerpt only.
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
The report documents agentic cyber workflows used by state-linked, criminal and hacktivist actors, including GTG-20006, GTG-50020 and GTG-50029.
Claim-level citations (34)
- supportsGTG-10007 built an autonomous exploit foundry and used the outputs in real intrusions: Anthropic says the actor extracted hundreds of megabytes of student personal data from an education-technology company and retrieved citizen names, phone numbers and home addresses from a Southeast Asian government agency.
GTG-10007 campaign impact
- supportsGTG-10007 built an autonomous exploit foundry and used the outputs in real intrusions: Anthropic reports a fleet of 13 standing collection agents running on a schedule without a human in the loop.
GTG-10007 autonomous collection-fleet loop
- supportsGTG-10007 built an autonomous exploit foundry and used the outputs in real intrusions: Anthropic says GTG-10007 targeted roughly 50 organizations and compromised an education-technology company, a retailer and a Southeast Asian government agency.
GTG-10007 hands-on intrusions
- supportsGTG-10007 built an autonomous exploit foundry and used the outputs in real intrusions: Anthropic reports that one continuously iterating exploit-research workflow in GTG-10007 produced more than a dozen possible zero-day findings in a month.
GTG-10007 appliance zero-day research loop
- supportsA dating-app network mixed thousands of AI personas with real workers: Anthropic reports roughly three AI personas for every real person mixed into the dating-app feed.
GTG-15001 key findings
- supportsA dating-app network mixed thousands of AI personas with real workers: Anthropic reports more than 4,700 AI personas engaging at least 25,000 unique people across a two-week window in a network of more than 20 dating apps.
GTG-15001 overview
- supportsA dating-app network mixed thousands of AI personas with real workers: Anthropic reports that the apps included review-specific behavior intended to hide their normal functionality during App Store and Play Store review.
GTG-15001 store-review evasion
- supportsA dating-app network mixed thousands of AI personas with real workers: Anthropic reports Claude-powered personas sending roughly 2.36 million messages over the two-week observation window.
GTG-15001 key findings
- supportsAnthropic says DeepSeek silently routed selected customer traffic through Claude: Anthropic reports that DeepSeek silently relayed selected user requests to Claude Opus while users believed they were using DeepSeek.
GTG-16001 overview
- supportsAnthropic says DeepSeek silently routed selected customer traffic through Claude: Anthropic attributes more than 12.1 million exchanges over 14 days in July 2026 to DeepSeek distillation attacks.
GTG-16001 scale
- supportsAnthropic says DeepSeek silently routed selected customer traffic through Claude: Anthropic says relayed traffic included sensitive company information, live Russian government database credentials and PRC police-surveillance development requests.
GTG-16001 sensitive-data examples
- supportsAnthropic attributes a large reasoning-trace extraction pipeline to Zhipu/Z.ai: Anthropic says Zhipu later used public vulnerability datasets to build capture-the-flag challenges and targeted the cyber capabilities of frontier models during distillation work.
GTG-16006 cyber-capability targeting
- supportsAnthropic attributes a large reasoning-trace extraction pipeline to Zhipu/Z.ai: Anthropic reports 770,609 exchanges through the chain-of-thought cleaner and more than three million Zhipu-attributed exchanges over the same 10-day period.
GTG-16006 scale
- supportsAnthropic attributes a large reasoning-trace extraction pipeline to Zhipu/Z.ai: Anthropic reports that Zhipu/Z.ai rotated through 273 fraudulent accounts during a 10-day chain-of-thought extraction campaign against Claude Opus 4.8.
GTG-16006 overview
- supportsGTG-20006 automated parts of a Russian espionage workflow: Anthropic says humans remained involved in target selection and workflow refinement even as agents automated substantial operational work.
Cyber operations trends and GTG-20006
- supportsGTG-20006 automated parts of a Russian espionage workflow: Anthropic reports that monitoring agents checked malware against security detections and automatically modified and rebuilt detected tools until they evaded those detections.
GTG-20006, malware adaptation
- supportsGTG-20006 automated parts of a Russian espionage workflow: Anthropic identified more than 20 organizations in GTG-20006 planning, reconnaissance or live operations, concentrated in government, defense, intelligence and diplomatic sectors.
GTG-20006, targeting
- supportsGTG-20006 automated parts of a Russian espionage workflow: Anthropic reports that GTG-20006 used customized AI-driven workflows from tool development and infrastructure acquisition through phishing, persistence, command-and-control and exfiltration.
GTG-20006, overview
- supportsGTG-50014 used agentic pipelines to turn exposed credentials into rapid multi-victim theft: Anthropic says one GTG-50014 operator used 10 AWS EC2 workers to download and scan 1.8 million Android APKs for hardcoded credentials.
GTG-50014 credential-harvesting pipeline
- supportsGTG-50014 used agentic pipelines to turn exposed credentials into rapid multi-victim theft: Anthropic says another compromise escalated from one stolen developer token to full administrative control of a victim cloud environment in roughly three hours.
GTG-50014 operational tempo
- supportsGTG-50014 used agentic pipelines to turn exposed credentials into rapid multi-victim theft: Anthropic reports a SaaS breach in which the operators extracted data from roughly 200 downstream customer organizations and dumped more than 2,100 Azure AD token sets spanning over 40 tenants in about 34 hours.
GTG-50014 supply-chain theft
- supportsGTG-50014 used agentic pipelines to turn exposed credentials into rapid multi-victim theft: Anthropic reports that one technology-provider compromise exfiltrated more than one terabyte of data including national identifiers and millions of payment-card records.
GTG-50014 serious compromises
- supportsGTG-50020 used prompt injection against an AI evaluation sandbox: Anthropic reports that a follow-on campaign from the same infrastructure attacked roughly 30 AI companies in about four days.
GTG-50020, follow-on campaign
- supportsGTG-50020 used prompt injection against an AI evaluation sandbox: Anthropic reports that GTG-50020 injected malicious instructions into an AI vendor's automated evaluation sandbox and caused it to disclose production AI API keys from multiple providers.
GTG-50020, AI supply-chain intrusion
- supportsGTG-50020 used prompt injection against an AI evaluation sandbox: The actor used parallel reconnaissance and exploitation agents and a containerized pentest platform that ran injection, XSS, authentication-bypass and SSRF testing with exploitation enabled against production systems.
GTG-50020, human-directed loop and autonomous exploitation pipeline
- supportsGTG-50020 used prompt injection against an AI evaluation sandbox: Anthropic says the actor pursued access to a pre-release Claude model through more than a dozen avenues but never obtained it, and that Anthropic's own systems were not compromised.
GTG-50020, campaign objective
- supportsA fake Claude reseller stole the credentials of the customers it claimed to serve: Anthropic says GTG-50021 advertised discounted Claude access while silently proxying customers to a different model.
GTG-50021 fraudulent reseller
- supportsA fake Claude reseller stole the credentials of the customers it claimed to serve: Anthropic describes stolen AI credentials as providing three attacker benefits: resale value, victim-funded compute and attribution cover.
AI credentials: loot, compute, cover
- supportsA fake Claude reseller stole the credentials of the customers it claimed to serve: Anthropic reports that the reseller tooling installed a credential harvester that stole Anthropic account credentials and sold them onward to other AI proxy resellers.
GTG-50021 credential theft
- supportsGTG-50029 used agentic workflows across a European hacktivist campaign: Anthropic reports that one compromised political campaign platform yielded about 140,000 records that included users' political opinions.
GTG-50029, political campaign platform
- supportsGTG-50029 used agentic workflows across a European hacktivist campaign: Anthropic estimates that the actor exfiltrated 12 to 26 GB of database dumps across affected targets and also obtained a 15,000-message mailbox.
GTG-50029, campaign scope
- supportsGTG-50029 used agentic workflows across a European hacktivist campaign: Across 42 tracked target entities, Anthropic reports internal access to at least 14.
GTG-50029, campaign scope
- supportsGTG-50029 used agentic workflows across a European hacktivist campaign: Anthropic reports that a single French-speaking actor used Claude and sub-agent workflows against European political parties, media, think tanks and SaaS providers.
GTG-50029, overview
- supportsGTG-50029 used agentic workflows across a European hacktivist campaign: Anthropic reports that the actor used Claude to develop and debug a previously undocumented WordPress re-installation race condition that created rogue administrator accounts and succeeded against at least four victim websites.
GTG-50029, novel exploitation
Cite this record
DiggingBeagle. “Countering misuse of AI: September 2026.” Published Sep 10, 2026 · Accessed Sep 14, 2026. https://diggingbeagle.com/sources/countering-misuse-of-ai-september-2026/
Citation guidance