Lifestyle

Anthropic's September Threat Report: Seven Kinds of AI Misuse and Targeted API Keys

Anthropic published a threat intelligence report on September 10, 2026, covering seven categories of AI misuse it disrupted between December 2025 and August 2026. This article explains what the report says and what it does not, and how ordinary people can guard against AI-enabled scams, protect their accounts and API keys, limit AI agent permissions, and report suspicious use.

Updated: About 10 min read

Original illustration of an AI misuse report alongside account and key protection
Image: Mokaair (© Mokaair)

On September 10, 2026, Anthropic published a threat intelligence report titled "Detecting and countering misuse of AI: September 2026," covering misuse of Claude that it detected and disrupted between December 2025 and August 2026. The report sorts the activity into seven categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. Its cyber operations section notes that most operations no longer amounted to simple question-and-answer chats, but were carried out or orchestrated directly by AI, and that API keys have become targets to be stolen and resold.

This article was fact-checked on September 15, 2026, based on the official web page, the report PDF, and the Claude Help Center. The cases, figures, and attributions in the report are Anthropic's own investigative conclusions, which this site cannot independently verify and has not tested. This article does not describe attack techniques in detail, and the everyday scenarios in it are examples designed by the editors.

What the Report Covers, and What It Does Not Mean

The report describes itself as the latest edition, following those published in March, August, and November 2025. The models misused were from the Claude Haiku, Sonnet, and Opus families; Anthropic says that, apart from one illicit distillation case, no case involved Fable- or Mythos-class models. In each case, Anthropic generally disrupted the activity or banned accounts, strengthened safeguards, and, where appropriate, shared intelligence with government authorities and industry partners.

The most important thing to keep in mind when reading this report is Anthropic's own framing: these cases are not typical misuse, but the most notable and novel activity it has found so far. They are individual cases that one vendor selected for disclosure from its own platform, not industry-wide statistics, and they cannot be used to compare which AI is safer.

The report names a number of companies and groups with suspected state backing. These attributions are likewise Anthropic's assessments, and the report does not include responses from those it names. The official page also provides an indicators of compromise file for security professionals.

Seven Categories of Misuse: Key Cases in the Report

Actors in the cyber operations section include suspected state-sponsored groups, financially motivated criminal groups, and hacktivists, and a single person or small team can use AI agents to go after multiple victims at once. The influence operations section includes 9 cases originating from Russia, Iran, Turkey, the Gulf, South Asia, Africa, and Europe. Tactics included fake accounts, fake news sites, and fictitious personas, but most of the content drew little or no authentic engagement.

The surveillance section covers cases from January to July 2026 involving China, Iran, West Africa, and commercial surveillance vendors. Of particular relevance to readers in Taiwan, Anthropic believes that an intelligence operation aligned with the Chinese government used Claude to build profiles of religious figures, including the leadership of the Presbyterian Church in Taiwan; in another case, Claude was used to monitor targets that included political figures in Taiwan. The conventional weapons section has 6 cases: 3 in China, 2 in Russia, and 1 in Yemen. The 5 cases in the biological misuse section deliberately withhold the institutions, countries, and pathogens involved, and Anthropic does not conclude that the researchers intended to cause harm.

The scams and fraud section has just one case: a Chinese app studio used Claude to build more than 20 dating apps in which AI personas posed as real people in chats. Over two weeks in April 2026, Anthropic found more than 4,700 AI personas in conversation with at least 25,000 users. The illicit distillation section is a one-sided allegation by Anthropic. The company says that since its first disclosure in February 2026, it has disrupted further attacks by 7 Chinese labs that used fake accounts to extract Claude's responses at scale to train their own models, and that several of them also fed their own users' conversations into Claude, most likely without those users' knowledge.

Checked on September 15, 2026; all figures are as stated in Anthropic's report and have not been independently verified by this site.
CategoryWhat the report describesOfficial figures or scope
Cyber operationsAI agents split up recon and intrusionOne case: about 30 AI companies attacked in about 4 days
Influence operationsFake accounts, fake news sites, fictitious personas9 cases; most drew little authentic engagement
SurveillanceAI in place of engineering and analysis staffCases from January to July 2026
Scams and fraudDating apps with AI personas posing as real peopleOver 4,700 personas in two weeks
Biological and conventional weaponsDual-use bio research, weapons softwareBio: 5 cases; weapons: 6 cases
Illicit distillationFake accounts extracting responses at scaleAllegation against 7 Chinese labs

From Chat to Agents: Why API Keys Became Spoils

Anthropic concludes that most cyber operations in this period were carried out or orchestrated directly by AI. Rather than simply asking a chatbot questions, actors used multi-agent frameworks to divide up reconnaissance, intrusion, and data theft, with humans mainly choosing targets and reviewing the results. The report also offers two caveats: humans still make the most critical decisions, and the degree of automation is a separate matter from the harm caused, since several of the most serious intrusions were in fact directed by a human at every step.

The report also says that none of these operations relied on new techniques defenders had never seen. They still used stolen login credentials, unpatched edge devices, internet-exposed services, phishing, and the like. What has changed is cost: reconnaissance, tool development, and data sorting that once took an entire team can now be handed to AI agents working in parallel.

According to the report, whoever obtains an AI key gets three things at once: loot that can be resold, compute paid for by the original owner, and cover, because the activity is recorded under the original owner's name. The report notes that these keys were often accidentally left by legitimate customers in public code, mobile app installation files, containers, websites, and chatbots; one hacktivist campaign ran for an entire month on stolen keys. Anthropic states that in two of the cases, the keys were stolen from customer environments and its own systems were not breached.

The report also documents a Russian-speaking criminal who tricked an AI vendor's automated evaluation sandbox into giving up production keys, then went on to attack about 30 AI companies in about 4 days. The goal was to obtain an unreleased Claude model, but every path toward it failed. Other groups sold Claude at low prices while actually routing the traffic to other models and stealing buyers' credentials. Anthropic recommends buying AI services only through authorized channels and protecting AI keys and agent integrations as production credentials.

Why API keys became spoils: the three uses the report identifies and the principle for protecting yourself
The report identifies three benefits attackers get from an AI key, and the principle of protecting keys as production credentials. · Image: Mokaair (© Mokaair)

What Individuals and Small Teams Can Do

Start with scams. Here is an example designed by the editors: Yun meets someone on a dating app who replies quickly and thoughtfully but always finds a reason to avoid video calls, while the app keeps prompting Yun to buy points to keep chatting. In the report's case, the AI personas were set up to deflect requests for video calls and photos, but the operator also recruited real people to handle video calls and social media follows. So fluent messages, or even a video call, are not enough to prove someone is trustworthy. Once the conversation turns to payments, investments, or requests for account details, pause and confirm through official channels you have looked up yourself.

For accounts, turning on two-step verification for the AI services, email, and cloud storage you use regularly is a basic step, but it is not a cure-all. The report mentions that attackers also steal session credentials issued after login, and that some websites use cheap AI services as bait to lure people into installing programs that impersonate popular AI tools and steal login information. So install AI tools only from official websites or channels the vendor has announced, and simply pass on unofficial intermediaries selling cheap AI services.

Small teams working with the API can check their practices against the API Key Best Practices in the Claude Help Center: do not share keys or post them in public forums, emails, or support tickets, even with Anthropic; store them in environment variables or encrypted secrets rather than writing them into code; use separate keys for development, testing, and production; rotate them regularly, for example every 90 days; and enable secret scanning on your code repositories. The report itself gives an example of a developer pasting service tokens into a Chinese lab's coding assistant, with the content then forwarded to Claude.

When granting permissions to AI agents, the principle is to keep them to a minimum. The places where the report says attackers search for leaked tokens include AI agents that victims deployed themselves. In a scenario designed by the editors, a three-person studio that has an AI agent sort client emails would grant it read access only to a designated mailbox and would not give it keys for payments or cloud management. The Help Center also recommends regularly reviewing key usage logs in the Console to spot anomalies early.

How to Report Suspicious Use, and How to Read Reports Like This

If you suspect your Claude API key has leaked, the Help Center recommends revoking it immediately: sign in to the Claude Console and delete the key on the API keys page. The Help Center also says that Anthropic participates in GitHub's Secret scanning partner program, so Claude API keys detected in public repositories are automatically deactivated and the user is notified by email.

If Claude's output, or a Claude conversation someone has shared, appears to violate the usage policies or local law, you can report it through the content reporting form listed in the Help Center, and shared conversation pages also have a report button. For model safety issues, the Help Center asks users to email usersafety@anthropic.com with enough detail to reproduce the problem. Do not include your own passwords or keys when reporting.

Reports like this show what AI misuse actually looks like, but there is no need to panic: most influence operation content drew little authentic engagement, and Anthropic explicitly says the biological cases do not mean Claude has already created an imminent biological threat. A more practical response is to use the occasion to review your own accounts, keys, and AI tool permissions.

Latest travel guides

Sources

Lifestyle