Suspected Russian spies used Claude to attack more than 20 organizations
Newsroom / Security and Privacy desk
Anthropic says a suspected Russian espionage crew used Claude to automate attacks on more than 20 organizations. It is the lead case in the company’s most detailed threat intelligence report so far, and it is far from the only one.
The lead case
The report, published on September 10, 2026, covers misuse Anthropic disrupted between December 2025 and August 2026. In the lead case, operators Anthropic suspects belong to the Midnight Blizzard group used Claude for reconnaissance and to set up phishing infrastructure. When security products detected their tools, they had the model rebuild the malware.
The targets included Ukraine’s government and drone component makers. In one breach, the group took more than 300,000 national identity records from a North African government.
The rest of the catalogue
The other cases show how widely AI assistance has spread across attack types. A single French-speaking hacktivist got inside 14 of 42 targeted European political parties, media outlets and think tanks. An Istanbul-based political operations firm asked for a dashboard setting to generate one million artificial views on the Malaysian prime minister’s account.
A recurring pattern runs through several cases: attackers stole their victims’ Anthropic API keys and moved their own attack workloads onto them. The victim paid for the compute, and the attacker gained cover.
Anthropic says it disrupted every operation described in the report and, where appropriate, shared what it found with authorities and other AI companies.
What changes for defenders
For companies, the most concrete lesson is about credentials. An AI API key is now valuable loot in its own right, both as free compute and as a way to hide activity inside a legitimate account. Keys should be scoped to the smallest set of permissions, rotated on a schedule, and monitored for sudden spikes in usage.
The broader point is that the report describes attackers using the same agentic workflows that developers use, applied end to end: planning, building, adapting when blocked. Detection now depends as much on how model providers watch their own platforms as on what defenders see on their networks.
Sources
ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.