ISLAMABAD: Artificial intelligence is rapidly changing the threat landscape as criminals, suspected state-sponsored groups, and politically motivated actors utilize AI systems to automate cyberattacks, surveillance, fraud, and disinformation campaigns, according to a recent report by the American AI company Anthropic.
In its "September 2026 Threat Intelligence Report," Anthropic said it identified and disrupted malicious activity involving its Claude AI models between December 2025 and August 2026.
The company said the cases show a significant evolution in how threat actors use AI.
“Rather than simply asking chatbots for advice, attackers are increasingly integrating AI into automated workflows capable of reconnaissance, exploitation, data theft, content production and other operational tasks.”
Anthropic described the emerging model as AI moving “from assistant to orchestrator,” with many operations involving multi-agent systems that can perform reconnaissance, exploitation and data exfiltration while humans remain involved mainly in setting targets and reviewing results.
Russian state-linked operation
One case involved a suspected Russian state-linked espionage operation targeting governments, diplomatic organizations, defense bodies and individuals connected to US foreign policy.
Anthropic said that AI-assisted workflows were used throughout the operation, from reconnaissance and phishing infrastructure to credential theft, persistence and data exfiltration.
The attackers also used AI to monitor whether their malware was being detected.
“When security products identified malicious software, AI agents helped modify and rebuild the malware in an effort to evade detection.”
Financially motivated cybercrimes
Financially motivated cybercriminals are also exploiting AI to accelerate mass attacks.
Anthropic identified suspected affiliates of the ShinyHunters collective using Claude to rapidly scan systems, search for exposed credentials and exploit vulnerable services.
In one case, attackers reportedly stole more than a terabyte of data, including national identifiers and millions of payment-card records.
Threats to AI industry
The report also highlights a growing threat to the AI industry itself.
It said, “Criminals are stealing API keys and session tokens, sometimes using compromised credentials to conduct attacks on other organizations.”
In one operation, an actor targeted around 30 AI companies in roughly four days after obtaining credentials from an AI vendor's evaluation environment.
The attacker sought access to a pre-release Claude model but failed to obtain it.
AI use for political manipulation
Beyond cybercrime, Anthropic reported extensive AI use for political manipulation and surveillance.
In Bangladesh, investigators identified a single actor who rotated through 29 Claude accounts to produce at least 1,500 fabricated headlines, 300 false narratives and 1,500 image-generation prompts.
The material was designed for distribution through Facebook, YouTube and TikTok and promoted pro-Awami League narratives while attacking political opponents.
Anthropic said that it found no evidence that the Awami League itself directed or funded the operation.
Other cases involved AI-generated political content, fake personas, impersonation and the laundering of state-backed narratives through supposedly independent media outlets.
Anthropic said Russian-linked operations used Claude to generate material that was later distributed through state-aligned outlets, while another operation targeting Iranian audiences used AI to impersonate a real activist and conduct conversations with the person's contacts.
Targeting opponents
Surveillance represents another major concern. Anthropic said that AI was used in operations targeting dissidents, journalists and minority communities, including an alleged China-linked campaign involving Uyghurs in Syria.
In another case, Iranian security-linked actors used Claude to develop surveillance tools and analyze large quantities of social-media data.
Anthropic said it banned the accounts involved, strengthened its detection systems and shared relevant intelligence with governments, technology companies and other partners.
The company argued that the findings demonstrate an urgent need for stronger safeguards across the AI ecosystem. As AI becomes more capable, the report warns, malicious actors may increasingly automate entire attack chains, compressing the time and resources required to run operations at previously unattainable scale.


