Anthropic, an AI research company, has issued a warning about the misuse of its AI models, known as Claude, by various malicious entities. Between December 2025 and August 2026, these models have been exploited in cyber attacks, weapons design, propaganda, and mass surveillance campaigns.
The entities, labeled as Generative Threat Groups (GTGs) by Anthropic, include state-sponsored actors, financially motivated criminals, commercial spyware vendors, and politically driven individuals. The AI company highlights how the advanced capabilities of AI models have bridged the gap between well-funded state operations and independent operators.
State-Sponsored Cyber Operations
Among the highlighted cases is a Russian-sponsored threat actor, GTG-20006, linked to Midnight Blizzard, which utilized AI to enhance their cyber capabilities. Other incidents involve GTG-50014, a French-speaking operator associated with the ShinyHunters collective, which executed credential-harvesting operations on a large scale.
A Chinese-based group, GTG-10007, reportedly used Claude for reconnaissance and intrusion attempts on foreign networks and developed exploits for security products. This group targeted various sectors globally, demonstrating the broad reach and impact of AI-assisted cyber campaigns.
Commercial and Financial Exploitation
GTG-50021, a Russian and Ukrainian-speaking group, ran a fraudulent operation reselling AI access while stealing credentials. Similarly, GTG-50020 targeted AI vendors to steal API keys, showcasing the financial motivations driving some of these operations.
Furthermore, GTG-50029 exploited vulnerabilities in European political organizations and media outlets, highlighting the wide-ranging targets of these threat actors. This group also developed a doxxing platform to cross-reference breached data.
Influence and Surveillance Campaigns
Anthropic has also identified numerous influence and surveillance campaigns utilizing Claude. These include GTG-04001, which engaged in information manipulation in the Central African Republic, and GTG-54002, linked to a commercial influence operation rewriting political content.
Other significant operations include GTG-54006 in Bangladesh, which promoted political narratives, and GTG-84006, which targeted Iranian audiences. These campaigns underline the potential of AI models to amplify influence operations at scale.
An alarming aspect is the misuse of AI in surveillance operations, such as GTG-30005, which developed intelligence-gathering capabilities targeting U.S. naval forces.
Conclusion
Anthropic’s findings reveal the extensive misuse of AI models in cyber operations worldwide. The company’s efforts to neutralize some of these threats highlight the ongoing challenges in ensuring the safe deployment of AI technologies. As AI continues to evolve, it is crucial for stakeholders to remain vigilant and implement necessary safeguards to prevent exploitation.
