Anthropic Details Russian, Chinese AI-Uplifted Ops on Claude
TL;DR
- Anthropic's report covers activity disrupted between December 2025 and August 2026 across seven harm areas including cyber operations, influence operations, biological misuse and distillation.
- A Russian cluster tagged GTG-20006 targeted more than 20 organizations, while a Chinese-speaking group in Changsha, Hunan hit roughly fifty across sectors.
- Nine influence operations spanned six continents, and one Russian-speaking actor hit around 30 AI companies in four days via a vendor sandbox breach.
Anthropic's September threat intelligence report covers activity the company disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Running through it is a leveling finding: "AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators."
A Russian espionage cluster the report tracks as GTG-20006 ran AI-assisted operations against Ukrainian, European and diplomatic targets. Anthropic writes that its investigation "identified more than 20 distinct organizations targeted in the actor's operational planning, reconnaissance, and live operations." A separate Chinese-speaking group, GTG-10007, likely residing in Changsha in China's Hunan province, was aimed at roughly fifty organizations spanning education, retail, energy, finance and manufacturing.
Influence operations dominate the report's scale numbers. Anthropic details "nine of those cases. They originated in Russia, Iran, Turkey, and across the Gulf, South Asia, Africa and Europe, and targeted audiences on six continents." One French-registered outfit ran approximately 70 fabricated news websites that published at least 8,913 articles in about 20 languages. An Istanbul-based operation ran roughly a thousand fake X/Twitter accounts targeting all 222 Malaysian parliamentary constituencies.
The AI supply chain surfaces as its own target category. A financially motivated Russian-speaking actor, GTG-50020, compromised an AI vendor's evaluation sandbox and hit around thirty AI companies in four days, seeking access to a pre-release Claude model — though, the company adds, "the actor never compromised Anthropic's own systems." Actors linked to ShinyHunters, meanwhile, harvested API keys from application repositories and cloud metadata endpoints and resold them.
For investigators, Anthropic states the takeaway plainly: "sophistication has stopped being a reliable signal of who is behind an operation." The report lands during a run of misuse disclosures from the company; our tracker logged Anthropic detailing four Claude cyber incidents and inviting METR to audit its detection work earlier the same week, one of 334 Anthropic stories we've logged in the last 90 days.
Originally reported by anthropic.com
Read the original article →Original headline: Anthropic Threat Report Disrupts Bio-Weapons Plots, Chinese Distillation and Russian Cyber Ops on Claude