Anthropic’s September 2026 threat report examines how AI misuse appears in real investigations, how safeguards respond, and where visibility remains limited.
* 00:00 - Introduction
* 00:09 - Overview
* 02:33 - Cyber operations
* 07:31 - GTG-20006: Russian espionage
* 18:37 - GTG-50014: ShinyHunters smash-and-grab opportunists
* 35:58 - GTG-10007: Exploit foundries and autonomous attack frameworks
* 45:22 - AI supply chain as target, loot, and attack compute
* 50:50 - GTG-50020: From hotel bookings to the AI supply chain
* 56:23 - GTG-50029: Hacktivists targeted European political and affiliated entities
* 01:02:35 - Prevailing trends
* 01:09:25 - Influence operations
* 01:17:49 - GTG-04001: Disrupting a Russian foreign information manipulation and interference operation in the Central African Republic
* 01:23:57 - GTG-54002: Disrupting a commercial “influence-as-a-service” operation spanning six continents
* 01:32:25 - GTG-84005: Disrupting a commercial election-manipulation platform targeting Malaysia
* 01:38:46 - GTG-24015: Disrupting Russian state-media editorial pipelines built on Claude
* 01:46:02 - GTG-34001: Disrupting Iranian state-aligned influence operations on Claude—the ICCO, the Islamic Propaganda Office, and the Bina Observatory
* 01:53:43 - GTG-54006: Disrupting an automated pro-Awami League fake-news operation on Claude targeting rural Bangladesh
* 01:59:23 - GTG-84006: Disrupting a distributed MEK/NCRI-aligned influence operation that used a shared AI agent to impersonate real people and recruit inside Iran
* 02:06:12 - GTG-54004: Disrupting a domestic coordinated inauthentic behavior campaign in Kenya
* 02:10:29 - GTG-84002: Disrupting a UAE-directed influence operation targeting the Muslim Brotherhood, Sudan conflict, and UN accountability mechanisms
* 02:14:47 - Surveillance operations
* 02:19:13 - GTG-54009: Disrupting a commercial surveillance platform using Claude to profile the social media accounts of Iranian and Persian Gulf-based users
* 02:24:35 - GTG-14010: Disrupting a China-based surveillance and recruitment operation targeting Uyghurs in Syria
* 02:30:02 - GTG-14020: Disrupting a China-based religious affairs intelligence operation targeting Catholic, Tibetan Buddhist, Falun Gong, and Taiwanese Christian communities
* 02:34:45 - GTG-14021: Disrupting a China-based public and state security campaign of “stability maintenance” surveillance and transnational repression
* 02:41:52 - GTG-14022: Disrupting a China-based “public opinion monitoring” and dissident surveillance operation
* 02:47:44 - GTG-34007: Disrupting two Iranian nexus actors building surveillance systems and malicious Firefox browsing extension
* 02:51:48 - GTG-50027: Disrupting a national mass interception and surveillance platform for Mali’s state intelligence service
* 02:55:03 - GTG-30004: Automating open-source intelligence and developing malware
* 02:56:30 - GTG-30005: Military reconnaissance
* 02:58:36 - GTG-30006: Building the tools for domestic surveillance
* 03:03:51 - Conventional weapons
* 03:07:48 - GTG-87001: Disrupting a Yemen-based guided weapons engineering cell using Claude to develop guidance software
* 03:11:14 - GTG-17001: Disrupting a China-based operation using Claude to draft a fire control specification and acquisition documents for undersea warfare
* 03:14:32 - GTG-27005: Disrupting a Russia-based operation using Claude to engineer an autonomous military drone swarm
* 03:18:38 - GTG-17002: Disrupting a China-based operation using Claude to build targeting software for electronic warfare and air defense suppression
* 03:22:41 - GTG-27006: Disrupting a Russia-based operation using Claude to procure mixed military and civilian goods
* 03:28:05 - GTG-17003: Disrupting a China-based operation using Claude to collect intelligence on directed-energy weapons and their supply chain
* 03:31:15 - Biological misuse
* 03:38:23 - Case study 1: An evasion platform for military-civilian research
* 03:43:23 - Case study 2: A research program engineering highly pathogenic mammal-adapted avian influenza
* 03:48:42 - Case study 3: Covert frontier model access for orthopoxvirus research
* 03:50:41 - Case studies 4 and 5: Venoms and toxins
* 03:54:55 - Conclusions
* 03:58:20 - Scams and fraud
* 03:58:23 - GTG-15001: Deceptive dating app network
* 04:05:16 - Illicit distillation
* 04:05:19 - Illicit distillation and scaled abuse
* 04:14:23 - GTG 16005: Chain-of-thought distillation and AI R&D campaign by Alibaba (Qwen / Tongyi Lab)
* 04:16:48 - GTG-16002: Moonshot serves Claude instead of Kimi and collects exchanges for model training
* 04:20:19 - GTG-16001: DeepSeek serves Claude instead of its own models and collects exchanges for model training
* 04:23:08 - GTG-16006: Distillation, AI R&D, and targeting cyber capabilities
* 04:25:52 - GTG-16008: Distillation campaign by Xiaomi
* 04:28:16 - GTG 16012 and GTG 16003: Sensetime, MiniMax, and the third-party reseller ecosystem
https://www.anthropic.com/threat-intelligence-report-september-2026
Get full access to Askwho Casts AI at askwhocastsai.substack.com/subscribe