Anthropic Threat Intelligence (misuse reporting programme)
The threat-intelligence function of Anthropic, the AI model vendor, which publishes a recurring public account of attempts to misuse its models, the enforcement action it took, and the intelligence it shared with authorities and industry partners.
What it publishes
- Series title: Detecting and countering misuse of AI (earlier editions: Detecting and countering malicious uses of Claude).
- Cadence: quarterly-ish โ March 2025, August 2025, November 2025, September 2026. Each edition covers activity disrupted since the previous one; the September 2026 edition covers December 2025 โ August 2026.
- Scope: seven harm areas โ cyber operations, influence operations, surveillance operations, conventional weapons, biological misuse, scams and fraud, and illicit distillation. Cyber operations is the largest section and the one most relevant to this wiki.
- Case structure: labelled case studies using the vendor's own Generative Threat Groups designators, with target sets, tooling, workflow descriptions, and IOC tables for selected cases.
- Models involved: Claude Haiku, Sonnet and Opus. The September 2026 edition states that no misuse cases involved Fable or Mythos-class models, except one illicit distillation case.
- Action taken: account and organisation bans, safeguard changes driven by what was observed, automated detections built from behavioural signatures, and intelligence sharing with government and industry partners.
Why it matters
It is a Tier 1 first-party source for AI-enabled intrusion tradecraft. The vendor is the primary observer of activity on its own platform, and its case studies carry detail โ workflow automation, target lists, stolen-key reuse, exploit development โ that news rewrites flatten into a single anecdote. When an aggregator reports "AI used to hack X", the underlying primary is usually one of these editions.
Limits and handling
- Attribution is the vendor's assessment. Actor naming and state links inside the reports are hedged claims, not corroborated fact. Carry the hedge.
- One platform's view. The cases describe actors who used this vendor's models and were detected doing so. That is a detection-biased sample: actors who used other models, or who evaded detection, do not appear.
- Disruption, not neutralisation. Several cases record that the actor was banned but the operation continued on other infrastructure or deployments.
- Not evenly detailed. The cyber-operations cases are rich; other harm areas vary in specificity.
Access
The programme's report landing pages sit at the site root as /threat-intelligence-report-<month>-<year> rather than under /news/, and the site publishes no RSS feed for either (all feed paths 404 as at 2026-09-11). Digest-side capture is therefore by HTML scrape through blogwatcher, using a selector that matches both /news/ posts and the report landing pages.
Related: Ai Uplift, Generative Threat Groups