For two decades, threat intelligence analysts treated craft as a fingerprint. A patient, multi-stage intrusion that rebuilt its own tooling when caught meant a government was paying the bills. A noisy smash-and-grab meant a teenager with a scanner. In a report published Thursday, Anthropic says that heuristic is finished.

“For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation,” the company wrote, noting that a lone hacktivist running on stolen API keys, a scattering of financially motivated criminals, and a state espionage operator each sustained multi-victim campaigns that a year earlier “would have required many skilled operators and specialist knowledge.”

The September 2026 report covers activity Anthropic says it identified and disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. The cases involved Claude Haiku, Sonnet and Opus models; Anthropic says none touched its newer Fable or Mythos-class systems, except one distillation case.

The centerpiece is GTG-20006, one of Anthropic’s internal Generative Threat Group designators. The company assesses the cluster as Russian state espionage and says its attribution is consistent with public reporting on the group commonly tracked as Midnight Blizzard; one operator used the handle JackPoterz. Targets included military intelligence bodies in Ukrainian and European governments, embassies, think tanks and people connected to U.S. foreign policy — more than 20 organizations in total. The group bulk-exported mailboxes at drone component manufacturers, stole a complete software development kit for a drone vision system, and in a separate intrusion at a North African government technology authority exfiltrated more than 300,000 national identity records.

What Anthropic flags as the structural change is not the targeting but the loop. When security products flagged the group’s implants, the report says, “agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections.” Anthropic argues this “inverted the cost back onto defenders,” since a newly deployed detection no longer buys time. A separate Chinese-speaking cluster, GTG-10007, ran what the company calls automated exploit foundries against roughly 50 organizations using agent swarms that persisted campaign memory between sessions; one workflow iterating on network appliance firmware “yielded more than a dozen possible zero day findings in a single month.” Two of the operators were identified as undergraduates. Affiliates of the ShinyHunters extortion collective dumped more than 2,100 cloud access tokens spanning more than 40 corporate tenants in about 34 hours, with AI agents performing nearly all of the work.

The AI supply chain itself now appears as a target rather than only a tool. Anthropic describes GTG-50020, a Russian-speaking actor that pivoted from hotel booking and fintech intrusions to AI vendors, planting malicious instructions in a vendor’s automated evaluation sandbox to extract the production API keys it held for multiple model providers. A follow-on campaign hit roughly 30 AI companies in about four days, seeking access to a pre-release Claude model. Anthropic says every path failed and its own systems were never breached. Elsewhere, the company says nine influence operations originating in Russia, Iran, Turkey and across the Gulf, South Asia, Africa and Europe reached audiences on six continents, including an editorial pipeline in which a former Sputnik Moldova editor-in-chief used Claude to generate Russian-language articles published on Sputnik channels and RIA Novosti. On distillation, Anthropic counted nearly 200 million exchanges across five campaigns attributed to seven China-based labs, with Moonshot AI and DeepSeek accused of silently forwarding their own customers’ requests to Claude — practices the report calls “likely inconsistent with privacy laws and the labs’ own terms of service.” Five biological misuse cases were disrupted; the report and this article describe them only at that level.

When capability is rented rather than built

Attribution has always been inference from scarcity. Writing reliable implants, maintaining them under detection pressure and running parallel intrusions required payroll and institutional memory only states could assemble. Those costs were the evidence. If a frontier model now supplies the labor on a metered basis, the evidence evaporates, and what remains is infrastructure, targeting and intent: slower, more ambiguous signals. That is a real problem for a profession whose public output is mostly confident naming.

It is also worth being precise about who is telling us this. The report is self-published by a vendor with a commercial interest in being seen as the responsible lab, and Anthropic is simultaneously in a competitive dispute with the Chinese labs it names. Researchers have noted the report omits indicators of compromise and the prompts used to defeat Claude’s safeguards — common in vendor threat intel, but it means the case studies cannot be independently checked. Some claims do have outside corroboration. A joint NSA, CISA and FBI advisory issued September 8 accused China-based AI companies of systematic distillation of U.S. frontier models. China’s Commerce Ministry has said such accusations have no factual or legal basis. Moonshot declined to comment; DeepSeek and Xiaomi did not respond to reporters.

Jacob Klein, Anthropic’s head of threat intelligence, framed the surveillance findings bluntly to Axios: “Authoritarian states are using AI for surveillance, repression and influence operations today. It’s no longer hypothetical.” He also conceded enforcement’s limits: actors pushed off Claude move to open-weight models, as Mali’s government did after Anthropic cut off its state surveillance platform.

Watch three things. Whether Google, OpenAI and Microsoft publish overlapping GTG-style findings that would let outsiders triangulate. Whether Congress, which has already asked Anthropic’s chief executive to testify on an earlier Chinese espionage campaign, moves from hearings to disclosure mandates. And whether defenders get anything resembling the closed detection loop that attackers, per this report, already have.

“For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation.”
— Anthropic Threat Intelligence team, September 2026 threat intelligence report
20+
Organizations targeted by the GTG-20006 cluster
~200 million
Exchanges tied to distillation across five campaigns
34 hours
Time to dump 2,100+ cloud tokens across 40+ tenants
9
Influence operations disrupted, across six continents