On Anthropic’s AI Misuse Report

Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings.

A few of the highlights:

  • AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs.
  • The report describes attackers using AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and the extraction of sensitive data from downstream organizations.
  • Influence operations used persistent agent memory, fake news sites, fabricated journalists, synthetic personas, political profiling, and large-scale multilingual content, although high content volume often produced little genuine engagement.
  • Surveillance and repression cases included automated dossiers, biometric and communications analysis, transnational targeting, coercive recruitment, and systems that continued operating locally after model access was revoked.
  • Biological and weapons cases show dual-use risk: AI supported advanced scientific and military work, but the report generally doesn’t establish completed biological weapons or operational battlefield deployment.

Posted on September 25, 2026 at 7:07 AM • 11 Comments

Comments

1st post kitty • September 25, 2026 7:23 AM

1st post kitty laughs
⠀⠀⠀⠀⢠⡶⠚⢷⣤⡀⠀⠀⠀⠀⠀⣲⡶⠛⠻⣆⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⢠⡿⠁⠀⠀⠙⣷⣄⠀⢀⣴⡟⠁⠀⠀⢷⢹⡆⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⣾⠃⠀⠠⠶⠚⠛⠛⠛⠛⠋⠀⠀⣀⡀⢸⠈⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⢸⣏⡔⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠚⠉⠉⣿⠀⢹⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⢾⠏⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⠀⢸⡇⠀⠀⠀⠀⠀⠀⠀⠀
⠀⢠⣿⢠⣶⡆⠀⠀⠀⠀⣀⣀⠀⠀⠀⠀⠀⠀⠀⠀⢸⡇⠀⠀⠀⠀⠀⠀⠀⠀
⢒⡾⠁⠘⠟⠁⠀⠀⠀⠀⣿⣿⡆⠀⠀⠀⠀⠀⠀⠀⢸⡇⠀⠀⠀⠀⠀⠀⠀⠀
⠉⣧⠀⠀⠀⠀⠃⠀⠀⠀⠈⠉⠠⣍⠀⠀⠀⠀⠀⠀⣸⡇⢀⣤⠶⠛⠛⠻⢦⣄
⠀⠸⣧⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣰⡟⣴⠟⠁⠀⠀⠀⠀⠀⢻
⠀⠀⠀⠛⣷⡦⠀⠀⠀⠀⠀⠀⠀⠀⣀⣀⣤⡴⠞⠋⢠⡟⠀⠀⠀⠀⠀⠀⢀⡾
⠀⠀⠀⢰⡿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⠳⣤⡀⢸⠃⠀⠀⠀⠀⢠⡶⠟⠁
⠀⠀⠀⣸⠇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⢷⣹⡄⠀⠀⠀⠀⣼⠀⠀⠀
⠀⠀⠀⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢿⣇⠀⠀⠀⠀⢹⡄⠀⠀
⠀⠀⠀⢸⡀⢀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣿⡄⠀⠀⠀⠈⣧⠀⠀
⠀⠀⠀⢸⡇⠘⡇⠀⠀⠀⠀⠀⠀⠀⣀⠀⠀⠀⠀⠀⠀⢸⣿⠀⠀⠀⠀⢹⡇⠀
⠀⠀⠀⢸⡇⠀⠙⠀⠀⠀⠀⠀⢠⠞⠁⠀⠀⠀⠀⠀⠀⠀⣿⠇⠀⠀⠀⢸⡇⠀
⠀⠀⠀⢸⡇⠀⢸⡆⠀⠀⠀⠀⣟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠛⠀⠀⠀⠀⣸⠇⠀
⠀⠀⠀⢸⣿⠀⠀⡇⠀⠀⠀⠀⣿⡀⠀⠀⠀⠀⠀⠀⠀⢀⡇⠀⠀⢀⣴⡟⠁⠀
⠀⠀⠀⠘⠿⠶⢶⢧⣦⣦⡴⢾⣥⣽⣤⣤⣤⣤⣤⣤⡴⣯⡤⠴⠶⠛⠋⠀⠀⠀
and laughs

Clive Robinson • September 25, 2026 8:47 AM

@ Bruce,

With regards,

“Daniel Meissler usefully summarized the report into 117 findings.”

Something tells me that the reality is this is just the tip off the iceberg that Anthropic dared “fess upto” in it’s AI Misuse Report.

Lets be honest we already know from the row with the current US Executive, that those in the top of the US Dept of War wanted to follow AI Usage in the way the IDF has…

Grumpy Old Coot • September 25, 2026 9:08 AM

Summary for you TL;DR folks: “Here is this tool can do all sorts of things that may or may not be ethical”… Some humans may not be ethical… “We are shocked and horrified that unethical humans are using our tool to do unethical things.”

KC • September 25, 2026 9:34 AM

Oh wow. Just started reading a section or two.

re: GTG-20006 Russian espionage

https://www.anthropic.com/threat-intelligence-report-september-2026

Anthropic reports the actor used AI (Claude?) to autonomously iterate their toolkits to evade known security defenses. Some toolkits were used for phishing, ClickFix, and DNS hijacking.

They identified at least 20 targeted organizations – primarily in Ukraine and Europe, but also in the Middle East and maritime agencies in Asia.

In one instance, the actor stole a SDK for a drone vision system. “They spent several days reverse-engineering the drone’s vision system, recovering its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product.”

Some indirect targets also included at least three hospitality vendors that operate hotel guest Wifi. They staged ClickFix lures to deliver Windows, Android, and iOS malware. Targets of particular interest included Ukrainian officials and drone manufacturers.

Every detail seems like a flashing news story. Wow.

GTG = Generative Threat Group

Untitled • September 25, 2026 10:17 AM

  • A small Russian freelance team developed drone-swarm software intended to choose targets, including people, and authorize detonation without human approval; those design goals do not establish successful battlefield deployment.

Only a small Russian freelance team? Evidence is that certain militaries are already doing this.
ht tps://www.theguardian.com/commentisfree/2026/sep/25/ai-israel-gaza-iran-police-surveillance

Clive Robinson • September 25, 2026 2:50 PM

@ Bruce, ALL,

Consider what the actual meaning is of,

“Anthropic published a long report detailing all of the Claude misuses it detected.”

The thing that should scare people is “it detected” and decided could go in such “a long report” that would be public.

Firstly ask how “it detected” and therefore what it actually missed?

Secondly ask after some were detected what thresholds and other constraints were acted upon with regards each of the “misuses it detected”?

If people think “these are all” the misuses then I can sadly say that you are effectively deluding yourself.

And I don’t mean that misuses are left out simply because Anthropic management is trying to protect it’s financial / investor position.

I’ve pointed out repeatedly that “technology is agnostic to use”. That is it has no morals, moors, or folkways of Human Society. It can at best follow rules imperfectly. Because it does not have the capability to judge the rules as society or it’s independent observers will.

Worse most humans are incapable of coming up with rules that are appropriately worded to be correctly enforceable.

As I point out you have two big issues,

1, Directing mind intent.
2, Is use good or bad as society views it and will do after the event.

Many years ago @Wael and I debated on this blog the problems with rules. I pointed out that,

“All rules should have exceptions.”

And @Wael only half joking added,

“Except for this one.”

It defines a fairly serious paradox in the way the world and society works and legislation fails because of it.

It’s enabled many a lobbyist to “weaponise legislation and regulation” to form cartels and monopolies. As one person said of Uber and similar “to draw up the bridge behind them”, so to deny others entry into the faux-market they had created.

Unfortunately it has enabled “bad legislation” that becomes “no exceptions”. That has been used to create considerable injustice as criminals and worse work out ways to use it to their advantage.

But worse still is society changes and the legislation rarely does or in a timely fashion.

This creates other problems and certain “vested interests” will almost certainly take advantage of it to commit abuse and harm “officially”.

The actual issue that few are prepared to talk about is that “good or bad” are human concepts applied by “third party observers” usually “long after the event”.

Before the event deciding “good or bad” is at best difficult humans get it wrong all the time. Guard-rails around LLM inputs and outputs are actually incapable of judging.

Worse guard-rails and sandboxes are not just non-prescient, they are easily mislead by a practiced human mind, and worse still it can be proved they always will be due to the “observer issue”.

That is if a first and second party to a communications collude in some way that is not known to a third party observer then a covert communications channel becomes available to the first and second parties. Worse still even if the third party knows of the method, they can still not prove that it is in use if the first and second parties chose to take further precautions such as employing “Shannon Perfect Secrecy”

Some years ago now I decided to investigate such systems out of curiosity, then as a form of “Deniable Encryption” such that an innocent looking “plain text” could contain a “covert message” that was secure against betrayal by the second party to the third party of the first party.

Having worked out a system that could do this by using “hand ciphers and codes” I described it on this blog a couple of times.

Little was I to realise at the time it would have major implications to the rapidly developing AI by LLM market.

Because it denies any claim that guard-rails and by logical extension sandboxes will stop undesired use of “Current AI LLM and ML Systems”.

Worse and this is the important point for this Anthropic Report, is it also means that much misuse of these AI systems will not be detectable by Anthropic or any other AI company. So not be seen or considered for putting in a report, be it by any AI company or more importantly some independent “oversight regulator”…

So it’s now time to ask the actual important question,

“If we can not now, or in the future, prevent AIs being used for harm by legislation, regulation, or even technology, what does humanity do?”

Thus we have the “Trolly Problem” philosophical question arising for AI, knowing there is “no answer” possible except “Do not create or allow use of AI”…

So you can see why some might think of AI as this generations “Thermonuclear Weapons” but “With globe spanning kill or fall out radius”.

lurker • September 25, 2026 6:34 PM

@Clive Robinson, ALL
“The thing that should scare people is “it detected” and decided could go in such “a long report” that would be public.”

Which raises the question of OpenAI’s intrusion to Australia Medicare. Open AI decided to tell the Australian govt on a basic public communications channel, not Australia CERT, nor the Medicare agency. And we may never know if the Oz authorities knew before they were told that they had been intruded. Some of the data read (we are told no writing) was public, but for the non-public data read it suggests maybe inadequqte defense.

Clive Robinson • September 25, 2026 7:03 PM

@ lurker, ALL,

With regards

“it suggests maybe inadequate defense.”

I think we’ve crossed a threshold where “attack by an army of AI agents” is now a “when not an if” for everyone who is a potential target.

Thus the question of,

“What makes me a target?”

It’s something that years ago made me think up and detail on this blog amongst other places why people should have a “two computer with gapping” as a minimum level defence strategy. One for “private” computing and the other for “public / communications”.

With the public communications computer ideally having only “non mutable memory” other than RAM. Such that a cycle of the “real” power switch would be sufficient to wipe out malware that had got on the computer.

The problem is getting such a computer these days…

lurker • September 25, 2026 9:45 PM

@Clive Robinson

Yebbut . . ; I’m talking about a government owned and operated server which is intended to be internet facing so that the public can read some of its files. Even if they followed your advice and had a totally separate machine for the non public files, nodern management practice is to allow those who are allowed to access those files, to do so from the comfort of their patio lounger, and not have to come into the office.

Yes, invitation to a security disaster. But also a disaster is that the owners operators apparently didn’t see any bogeymen in their system, suggesting a zero day – bad news and bad luck; or access tokens (of whatever form) left lying round – and those I fear will be with us forever, like death and taxes. Genie AI Agents only reduce the labour input from the controlling mind directing the exploit.

Clive Robinson • September 26, 2026 12:39 AM

@ lurker,

I chose not to talk about the server end, because of the fact the Security people want to have a job to put food on the table and a roof over the family head.

Which means that they get orders from manglement that come from others…

Quite Some years ago I put up a server for someone that was in effect “static” so it could be continuously tested and compared by a computer acting as a connected client to a DVD image of what the site should give. If it differed an alarm was raised.

It caught several attacks whilst they were in play and enabled fast response.

However “static sites” don’t do much for marketing and similar people these days because they are not “dynamic and exciting” or “interactive” etc etc etc.

Thus automated testing of a web sites got at best complicated, at worst the victim of internal politics.

Which is what your “yebbut” is in effect indicating from another aspect.

ICT System Security of all types ultimately rests on a “root of trust” to do authentication and access control.

Again years ago long before mandatory home working was pushed by nature, I was moaning about the lack of “role based systems” mostly from the users client end, but it was even more absent from the server end.

I could give a long litany on the security failings of not having role based authentication as the norm and how it got us into the mess we are in but I suspect I would be preaching to the choir choristers.

Systems Security whilst it contains a modicum of human management is mostly a technical subject and functional domain.

There is a truism of,

“Do not use technological systems to address societal issues.”

And ICTsec is increasingly subject to this observation.

But also a management failing that solutions can be “just bought in”. Which also has a truism,

“Throwing money at a problem probably won’t solve it, but you will certainly be poorer for the experience.”

I suspect many will recognise these issues hence the mess ICT Sec is in.

But there is a “third party” not mentioned developers of a certain mindset that even they describe as,

“Run fast and break things.”

As a known physical law of “a half M V squared” should give warning of the pain of such a design / development strategy can cause…

Oh and the engineering truism of,

“Exponentially proportional to the inverse of sensible design practice”

The result is something that has long been simmering in the pot, is coming out with AI.

Called “Value Sensitive Design”(VSD) it is a series of concepts that have been amalgamated into “a thing” that might be seen as an eventual method touted by consultants.

Having seen so many “methods” try and fail and leave behind their worst bits, I’m not looking forward to “this pudding coming out the pot”,

https://en.wikipedia.org/wiki/Value_sensitive_design

‘https://www.techtarget.com/it-strategy/definition/What-is-value-sensitive-design

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.