Anthropic threat report documents state-linked misuse and industrial-scale distillation
On 10 September 2026 Anthropic published its fourth threat intelligence report, covering operations it detected and disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit model distillation. The company said it had interrupted attempts to use Claude for biological weapons work and a suspected Russia-linked cyber-espionage campaign directed at Ukraine. It also attributed to Alibaba what it called the largest distillation campaign it has measured: more than 151 million Claude exchanges between May and July 2026, peaking near three million per day across more than 3,500 accounts it deemed fraudulent, which it said were used to train Qwen models. Campaigns attributed to Moonshot AI and DeepSeek were also described. The cases involved Claude Haiku, Sonnet and Opus models.
Why It Mattered
The report is one of the few systematic, case-based records of how frontier models were actually misused in this period, written by the party with direct telemetry, and it will be cited as evidence long after the individual operations are forgotten. Three things in it matter for the record. First, the operating pattern Anthropic first described in late 2025 — an agent running the attack chain rather than a human assisted by a model — appears across every class of actor it investigated, from state-linked services to ordinary criminals, which narrows the practical gap between well-resourced and unresourced attackers. Second, access to frontier capability itself became a target: stolen API keys and session tokens function as loot, which changes the security perimeter for model providers from the weights to the credential. Third, and most consequential geopolitically, the distillation findings put named Chinese laboratories at the centre of an allegation that had previously circulated as suspicion and US government assertion. A figure like 151 million exchanges is the kind of specific, dated, provider-measured claim that trade regulators, export-control authorities and litigants can act on, and it arrives while distillation's legal status is unsettled — China has argued the practice is legitimate. The report is a company-authored investigation and not independently audited, which is itself part of the historical picture: in 2026 the most detailed public accounting of AI misuse came from the vendors whose commercial interests it touched, because no regulator had equivalent visibility. Anthropic said none of the cases involved its most capable Fable or Mythos-class models apart from a single distillation case.
Who Built It
Anthropic
Applications
- Cybersecurity
- Threat Intelligence
- Biosecurity