Lifestyle
Anthropic's September Threat Report: Seven Kinds of AI Misuse and Targeted API Keys
Anthropic published a threat intelligence report on September 10, 2026, covering seven categories of AI misuse it disrupted between December 2025 and August 2026. This article explains what the report says and what it does not, and how ordinary people can guard against AI-enabled scams, protect their accounts and API keys, limit AI agent permissions, and report suspicious use.
Updated: About 10 min read

On September 10, 2026, Anthropic published a threat intelligence report titled "Detecting and countering misuse of AI: September 2026," covering misuse of Claude that it detected and disrupted between December 2025 and August 2026. The report sorts the activity into seven categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. Its cyber operations section notes that most operations no longer amounted to simple question-and-answer chats, but were carried out or orchestrated directly by AI, and that API keys have become targets to be stolen and resold.
This article was fact-checked on September 15, 2026, based on the official web page, the report PDF, and the Claude Help Center. The cases, figures, and attributions in the report are Anthropic's own investigative conclusions, which this site cannot independently verify and has not tested. This article does not describe attack techniques in detail, and the everyday scenarios in it are examples designed by the editors.
What the Report Covers, and What It Does Not Mean
The report describes itself as the latest edition, following those published in March, August, and November 2025. The models misused were from the Claude Haiku, Sonnet, and Opus families; Anthropic says that, apart from one illicit distillation case, no case involved Fable- or Mythos-class models. In each case, Anthropic generally disrupted the activity or banned accounts, strengthened safeguards, and, where appropriate, shared intelligence with government authorities and industry partners.
The most important thing to keep in mind when reading this report is Anthropic's own framing: these cases are not typical misuse, but the most notable and novel activity it has found so far. They are individual cases that one vendor selected for disclosure from its own platform, not industry-wide statistics, and they cannot be used to compare which AI is safer.
The report names a number of companies and groups with suspected state backing. These attributions are likewise Anthropic's assessments, and the report does not include responses from those it names. The official page also provides an indicators of compromise file for security professionals.
Seven Categories of Misuse: Key Cases in the Report
Actors in the cyber operations section include suspected state-sponsored groups, financially motivated criminal groups, and hacktivists, and a single person or small team can use AI agents to go after multiple victims at once. The influence operations section includes 9 cases originating from Russia, Iran, Turkey, the Gulf, South Asia, Africa, and Europe. Tactics included fake accounts, fake news sites, and fictitious personas, but most of the content drew little or no authentic engagement.
The surveillance section covers cases from January to July 2026 involving China, Iran, West Africa, and commercial surveillance vendors. Of particular relevance to readers in Taiwan, Anthropic believes that an intelligence operation aligned with the Chinese government used Claude to build profiles of religious figures, including the leadership of the Presbyterian Church in Taiwan; in another case, Claude was used to monitor targets that included political figures in Taiwan. The conventional weapons section has 6 cases: 3 in China, 2 in Russia, and 1 in Yemen. The 5 cases in the biological misuse section deliberately withhold the institutions, countries, and pathogens involved, and Anthropic does not conclude that the researchers intended to cause harm.
The scams and fraud section has just one case: a Chinese app studio used Claude to build more than 20 dating apps in which AI personas posed as real people in chats. Over two weeks in April 2026, Anthropic found more than 4,700 AI personas in conversation with at least 25,000 users. The illicit distillation section is a one-sided allegation by Anthropic. The company says that since its first disclosure in February 2026, it has disrupted further attacks by 7 Chinese labs that used fake accounts to extract Claude's responses at scale to train their own models, and that several of them also fed their own users' conversations into Claude, most likely without those users' knowledge.
| Category | What the report describes | Official figures or scope |
|---|---|---|
| Cyber operations | AI agents split up recon and intrusion | One case: about 30 AI companies attacked in about 4 days |
| Influence operations | Fake accounts, fake news sites, fictitious personas | 9 cases; most drew little authentic engagement |
| Surveillance | AI in place of engineering and analysis staff | Cases from January to July 2026 |
| Scams and fraud | Dating apps with AI personas posing as real people | Over 4,700 personas in two weeks |
| Biological and conventional weapons | Dual-use bio research, weapons software | Bio: 5 cases; weapons: 6 cases |
| Illicit distillation | Fake accounts extracting responses at scale | Allegation against 7 Chinese labs |
From Chat to Agents: Why API Keys Became Spoils
Anthropic concludes that most cyber operations in this period were carried out or orchestrated directly by AI. Rather than simply asking a chatbot questions, actors used multi-agent frameworks to divide up reconnaissance, intrusion, and data theft, with humans mainly choosing targets and reviewing the results. The report also offers two caveats: humans still make the most critical decisions, and the degree of automation is a separate matter from the harm caused, since several of the most serious intrusions were in fact directed by a human at every step.
The report also says that none of these operations relied on new techniques defenders had never seen. They still used stolen login credentials, unpatched edge devices, internet-exposed services, phishing, and the like. What has changed is cost: reconnaissance, tool development, and data sorting that once took an entire team can now be handed to AI agents working in parallel.
According to the report, whoever obtains an AI key gets three things at once: loot that can be resold, compute paid for by the original owner, and cover, because the activity is recorded under the original owner's name. The report notes that these keys were often accidentally left by legitimate customers in public code, mobile app installation files, containers, websites, and chatbots; one hacktivist campaign ran for an entire month on stolen keys. Anthropic states that in two of the cases, the keys were stolen from customer environments and its own systems were not breached.
The report also documents a Russian-speaking criminal who tricked an AI vendor's automated evaluation sandbox into giving up production keys, then went on to attack about 30 AI companies in about 4 days. The goal was to obtain an unreleased Claude model, but every path toward it failed. Other groups sold Claude at low prices while actually routing the traffic to other models and stealing buyers' credentials. Anthropic recommends buying AI services only through authorized channels and protecting AI keys and agent integrations as production credentials.
What Individuals and Small Teams Can Do
Start with scams. Here is an example designed by the editors: Yun meets someone on a dating app who replies quickly and thoughtfully but always finds a reason to avoid video calls, while the app keeps prompting Yun to buy points to keep chatting. In the report's case, the AI personas were set up to deflect requests for video calls and photos, but the operator also recruited real people to handle video calls and social media follows. So fluent messages, or even a video call, are not enough to prove someone is trustworthy. Once the conversation turns to payments, investments, or requests for account details, pause and confirm through official channels you have looked up yourself.
For accounts, turning on two-step verification for the AI services, email, and cloud storage you use regularly is a basic step, but it is not a cure-all. The report mentions that attackers also steal session credentials issued after login, and that some websites use cheap AI services as bait to lure people into installing programs that impersonate popular AI tools and steal login information. So install AI tools only from official websites or channels the vendor has announced, and simply pass on unofficial intermediaries selling cheap AI services.
Small teams working with the API can check their practices against the API Key Best Practices in the Claude Help Center: do not share keys or post them in public forums, emails, or support tickets, even with Anthropic; store them in environment variables or encrypted secrets rather than writing them into code; use separate keys for development, testing, and production; rotate them regularly, for example every 90 days; and enable secret scanning on your code repositories. The report itself gives an example of a developer pasting service tokens into a Chinese lab's coding assistant, with the content then forwarded to Claude.
When granting permissions to AI agents, the principle is to keep them to a minimum. The places where the report says attackers search for leaked tokens include AI agents that victims deployed themselves. In a scenario designed by the editors, a three-person studio that has an AI agent sort client emails would grant it read access only to a designated mailbox and would not give it keys for payments or cloud management. The Help Center also recommends regularly reviewing key usage logs in the Console to spot anomalies early.
How to Report Suspicious Use, and How to Read Reports Like This
If you suspect your Claude API key has leaked, the Help Center recommends revoking it immediately: sign in to the Claude Console and delete the key on the API keys page. The Help Center also says that Anthropic participates in GitHub's Secret scanning partner program, so Claude API keys detected in public repositories are automatically deactivated and the user is notified by email.
If Claude's output, or a Claude conversation someone has shared, appears to violate the usage policies or local law, you can report it through the content reporting form listed in the Help Center, and shared conversation pages also have a report button. For model safety issues, the Help Center asks users to email usersafety@anthropic.com with enough detail to reproduce the problem. Do not include your own passwords or keys when reporting.
Reports like this show what AI misuse actually looks like, but there is no need to panic: most influence operation content drew little authentic engagement, and Anthropic explicitly says the biological cases do not mean Claude has already created an imminent biological threat. A more practical response is to use the occasion to review your own accounts, keys, and AI tool permissions.
2026 AI News Roundup: Highlights and Daily Life Applications from January to September2026 AI News Roundup: Highlights and Daily Life Applications from January to SeptemberOrganizing key AI news stories month by month from January to September 2026, linking to full analyses in five languages. Covering models, work tools, creation, costs, and transparency, explaining backgrounds, uses, and limits.Read the full article
Project Glasswing and Mythos Preview: After AI Finds Vulnerabilities, the Real Work BeginsProject Glasswing and Mythos Preview: After AI Finds Vulnerabilities, the Real Work BeginsReviewing Anthropic's 2026 launch of Project Glasswing and Claude Mythos Preview, exploring the standard maintenance workflow and website management essentials from identifying candidate vulnerabilities to deploying defensive patches.Read the full article
Lifestyle
NVIDIA launches DGX Spark 64GB: on sale October 23 from $4,999, two units can be linked into 128GB
On October 2, 2026, NVIDIA announced a more affordable 64GB memory version of its DGX Spark personal AI computer, available from October 23 through six makers including Acer and ASUS. It is aimed mainly at developers and researchers who want to run AI models on their own machines. Below we summarize the specs NVIDIA published, its claims about linking two units, and what it means for general readers.
Lifestyle
Google Cloud Launches Spanner Queues: Putting Message Queues Inside Database Transactions to Make AI Agents More Reliable
Google Cloud has announced the general availability of Spanner queues, which make message creation part of a database transaction. The aim is to stop AI agents' "state" and "actions" from falling out of sync. This article covers Google Cloud's claims, the main features, and what it means for general readers.
Lifestyle
GPT-6.1 Sol Launches: New Sol Version in the API, Codex and ChatGPT Work, Not in Chat
OpenAI launched GPT-6.1 Sol on September 29, 2026, with the API name gpt-6.1-sol. The launch rollout covers Codex and ChatGPT Work on Plus, Pro, Business, Enterprise and Edu (Enterprise and Edu need an administrator to enable it); Free and Go are not included at launch, and it is not in Chat (checked September 2026).
Lifestyle
Claude Sonnet 5.5 Launches: Same List Price as Sonnet 5, Available in the API, on Cloud Platforms and in Claude.ai
Anthropic launched Claude Sonnet 5.5 on September 28, 2026. API list prices are the same as Sonnet 5 ($2 per million input tokens, $10 per million output tokens). It is available in Claude.ai, the API and several cloud platforms, and higher-risk cybersecurity requests fall back to Sonnet 5 (checked September 2026).
Articles that cite this one
Latest travel guides

GuideTokyo
Where to Stay in Tokyo: Comparing Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza, Plus Airport Access, Accommodation Tax, and Luggage Delivery
Where should you stay in Tokyo? Compare Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza by the same criteria: access from Narita and Haneda, transit routes, nearby attractions, neighborhood character, and who each area suits. Includes a comparison table, a Yamanote Line diagram, Tokyo’s accommodation tax as verified in 2026/9 (changing to 3% in 2027/4), and Airport TA-Q-BIN luggage shipping rules.
- Budget
- Hotels

GuideTokyo
How to Choose Tokyo Transit Passes: Are Suica, Welcome Suica, the Tokyo Subway Ticket, and the JR Pass Worth It?
On a first Tokyo trip, start with an IC card and pay per ride (Welcome Suica has no deposit and is valid for 28 days). If you take four or more subway rides in a day, add a 72-hour Tokyo Subway Ticket for 2,000 yen; a JR Pass is never worthwhile if you stay in Tokyo and do not go to Kansai. See what TOURIST PASMO, Suica on iPhone, and the Tokyo Metro day pass do and do not cover, with a decision chart. Prices verified in September 2026.
- Transport
- Budget

GuideTokyo
Tokyo Disneyland and DisneySea Guide: Ticket Prices, Fantasy Springs, Disney Premier Access (DPA), Standby Pass, and Which Park to Choose for Your First Visit
Tokyo Disney one-day Passport prices vary: most weekdays in 9/2026 cost ¥9,900 and weekends ¥10,900. At 14:00 daily, tickets go on sale for the same date two months later. Free Priority Pass is no longer on the official service list; only paid Disney Premier Access (¥1,000–3,500 per person per use) shortens waits. Covers hours, the 25th anniversary, Standby Pass, Entry Request, Fantasy Springs access and first-visit park choice; checked on the official site in 9/2026.
- Itineraries
- Family