
Anthropic’s September 2026 report says Claude was used to automate parts of live cyber and fraud operations, including phishing, credential theft, and exfiltration.
Anthropic’s September 2026 misuse report says Claude was used to automate and orchestrate parts of real cyber and fraud operations between December 2025 and August 2026, not just to generate text or code on demand. Across seven harm areas, the company describes attackers using Claude to support reconnaissance, phishing, exploitation, persistence, exfiltration, and rapid retooling when detections appeared. One of the clearest patterns is that AI is now sitting inside live attack workflows, helping operators move faster from phishing setup to stolen credentials and data theft.
Claude in the middle of live phishing, theft and exfiltration
The report spans seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Anthropic says the misuse cases involved Claude Haiku, Sonnet, and Opus. The core shift is operational. Instead of being used as a lightweight assistant for one-off prompts, Claude was used as a working layer inside offensive chains that ran from early reconnaissance through exploitation and persistence, then on to exfiltration and tooling changes when defenders started blocking activity.
That matters in practical terms because it cuts the time attackers need to adapt. If a phishing lure, malware build, or access method stops working, the same workflow can be reworked quickly instead of waiting on slower manual tradecraft. For operators, the change is straightforward: AI-assisted abuse is no longer limited to spammy chatbot misuse or generic coding help. It is showing up in the mechanics of account takeover, credential theft, and downstream access expansion.
GTG-20006 and the automation of espionage work
Anthropic identifies GTG-20006 as a Russian-linked espionage cluster that used AI-driven workflows to automate large parts of its operation. The report ties the cluster to phishing infrastructure, malware rebuilding, credential theft, and exfiltration across government, diplomatic, defense, and drone-related targets. It also says the group targeted more than 20 distinct organizations and scanned email services and remote-access systems across more than two dozen Ukrainian government organizations.
The operational detail is what stands out. Claude was not described as a side tool for drafting messages; it was part of a workflow that kept campaigns moving as infrastructure changed and detections appeared. Anthropic also says GTG-20006 ran a Microsoft 365 token-theft campaign against at least eight organizations. For defenders, that is the key consequence: once access operations are partially automated, phishing, credential theft, and exfiltration can be repeated across targets with less friction and less time between attempts.
ShinyHunters-linked operations moved from one credential to wider customer access
The report also tracks a financially motivated cluster tied to ShinyHunters. Anthropic says the group used AI to accelerate credential harvesting, breach access, supply-chain compromise, and extortion. In the cases highlighted, the activity did not stop at the first foothold: attacks could move from a single stolen credential or token into broader downstream customer access.
That pattern is especially relevant for business operators whose workflows depend on shared accounts, API-connected tools, or partner access. A lone credential leak is no longer just a single-user problem if attackers can quickly use AI-assisted workflows to map connected systems, test access paths, and widen the blast radius. Anthropic’s broader warning is that AI is lowering the skill barrier for serious cyber operations while shrinking defenders’ response window, because attacker tooling can change faster than static detections can be deployed.
Why the defender window is getting shorter
Anthropic’s report argues that the main security shift is speed. Attackers can use AI to rebuild lures, rewrite malware components, adjust exploitation steps, and keep exfiltration pipelines running with less manual effort. A separate Chinese-speaking espionage operation tracked as GTG-10007 underscores the point: Anthropic says it used Claude as an engineering and orchestration layer for vulnerability research, exploit development, malware work, and intelligence collection, with multiple operators running parallel workstreams.
For teams that manage customer communications, support flows, or messaging-linked identities, the immediate takeaway is tighter secrets handling, stronger access controls, and monitoring for automated abuse patterns rather than waiting for obvious manual intrusion signs. Static defenses matter less if attackers can retool quickly after each block. Some case-study details in the accessible report excerpt remain incomplete, but the central finding is clear: AI is now being used to operationalize phishing, credential theft, and exfiltration in live campaigns.
Disclaimer: This article was created with the assistance of AI. Images are for illustrative purposes only.
About the author

Samarth Agrawal is an AI and technology professional who writes about WhatsApp, automation, and emerging AI trends. He focuses on simplifying complex tech updates into practical insights for businesses, creators, and everyday users
