The short version
- Anthropic says its latest threat intelligence work found malicious attempts to use Claude across seven major harm areas
- The cases include cyber operations influence activity surveillance scams fraud biological misuse weapons related work and illicit model distillation
- Anthropic says it disrupted the operations and used the findings to strengthen safeguards and share intelligence
Anthropic’s Threat Intelligence team has published a broad threat intelligence report showing how malicious actors are using generative AI as part of real operations rather than only experimenting with chatbots. The company says its investigators identified and disrupted activity involving Claude across cyber operations influence campaigns surveillance scams and fraud biological misuse conventional weapons development and model distillation.
The report covers activity observed over several months and includes Claude Haiku Sonnet and Opus models. Anthropic says the cases were selected because they represented some of the most notable and novel misuse it had identified rather than because they represented ordinary use of the service.
AI is reducing the amount of specialist work attackers need to do themselves
The cyber cases are particularly important because AI can remove repetitive work from an operation. Reconnaissance document processing code generation translation and data analysis can all be delegated to a model. That does not mean a model can independently complete every attack but it can reduce the amount of manual effort required at several stages.
Anthropic’s report also describes misuse outside cybersecurity. The company identified operations involving influence activity surveillance fraud biological research weapons related work and attempts to extract model capabilities through illicit distillation. That range shows why AI safety cannot be treated as a single content moderation problem.
One of the more important technical details is that the company is using the incidents to improve detection. The Threat Intelligence team works with Anthropic’s safeguards teams to identify patterns of misuse and turn those observations into controls. Where appropriate the company says it also shares information with authorities and other organizations.
The report is less about one bad prompt and more about how capable models become components inside larger operational systems
Anthropic threat intelligence reporting
The distinction matters for developers building legitimate agents. A model can be safe in isolation while the surrounding application creates a new misuse path through unrestricted tools credentials or network access. Controls therefore need to consider the complete workflow including who can invoke the model what it can reach and how suspicious activity is detected.
Anthropic’s report also reinforces the importance of model supply chain security. Distillation attempts can allow another organization to extract useful behavior from a capable model and reproduce parts of that capability elsewhere. That turns model access controls into a technical security concern rather than only a commercial licensing question.
The report provides a detailed snapshot of the current misuse landscape while making clear that the cases are not representative of every Claude interaction. Its value is in showing the kinds of operational patterns that a frontier model provider is actively looking for and the safeguards being built in response.
Some of the cases also show why access controls remain important even when a provider has strong model safeguards. An attacker can combine a model with external services accounts proxy infrastructure and automation. The resulting system may have capabilities that are not obvious from a single conversation with the model.
Anthropic’s reporting approach also illustrates a growing security practice among frontier labs. Providers are increasingly publishing incident patterns rather than only model benchmarks. That gives defenders information about how AI systems are being incorporated into attacks and where conventional security monitoring may need to adapt.