ANTHROPIC · THREAT INTELLIGENCE

Anthropic's September 2026 AI misuse report: From assistant to attack orchestrator

The report covers disrupted activity from December 2025 through August 2026, including agentic workflows, phishing, and AI use across attack stages.

Source update: no separate date foundUpdated 14 September 2026Approx. 6 min read
Official Anthropic artwork for its September 2026 AI misuse report
Official Anthropic artwork for its September 2026 AI misuse reportOriginal image: Anthropic
News summary

Anthropic reports misuse of Claude that it detected and disrupted between December 2025 and August 2026 across seven harm areas. The company states that these are notable and novel case studies, not representative statistics for all use.

Best for: Security leaders, SOC teams, AI developers, and administrators controlling agent access to enterprise systems.

Points for a team pilot

Report signalAnthropic's evidenceEnterprise control
Agentic workflowsAI coordinated multiple steps while people selected targets or reviewed exfiltrationSeparate agent identities, limit tools, and approve consequential actions
Phishing/credentialsWorkflows researched domains, configured hosting, sent mail, and monitored control channelsProtect tokens, require MFA, and alert on anomalies
Supply chainTargets included government, defense, vendors, and Asia-based maritime agenciesReview supplier access, repository secrets, and external accounts

Publication date versus incident period

Anthropic published the report on September 10, 2026, but the reported activity occurred and was disrupted from December 2025 through August 2026. The cases should not be described as all occurring on publication day.

What is new

The report describes a move from one-off assistance toward AI executing and coordinating workflow stages, including reconnaissance, tool development, and phishing, while people still selected targets and reviewed stolen data.

Report limits

The evidence comes from activity Anthropic observed on its service, and the authors say the case studies are unusual rather than typical. Use them as threat scenarios, not an incident-rate estimate for Thailand.

Implications for Thai organizations

Organizations connecting agents to email, repositories, cloud systems, or MCP should inventory permissions and secrets, alert on unusual use, and require human approval before sending messages, changing infrastructure, or exporting data. No separate source-update date was found.

Before getting started

  • Inventory agents, plugins, MCP servers, and API keys
  • Use least privilege and short-lived credentials
  • Alert on bulk export and abnormal token use
  • Enforce phishing-resistant MFA
  • Tabletop an agent or tool-account compromise

Frequently asked questions

Does this mean Claude is unsafe?

No. It documents attempted misuse and disruption; it is not a comparative product-safety benchmark.

Can the reported target counts estimate Thai risk?

No. They belong to specific case studies and should inform scenarios and controls, not a base rate.

Continue with practical guidance for evaluation and procurement.

Claude Pro vs Team vs EnterpriseAI procurement checklist
OFFICIAL & REFERENCE SOURCES

Sources used for verification

Vendor facts are separated from TechTouch guidance. Features, pricing, and commercial terms may change, so confirm the latest information at the time of purchase.

01Anthropic — Detecting and countering misuse of AI: September 2026