New Delhi: State-linked hackers, government propaganda bodies and financially motivated criminals used the AI company Anthropic’s Claude models to automate cyberattacks, build surveillance systems and run influence operations across several countries, according to a report published Thursday by the company.

The report, ‘Detecting and countering misuse of AI: September 2026’, covers the period from December 2025 to August 2026 and sets out cases across seven areas, including cyber operations, influence campaigns and surveillance.Its central finding, Anthropic said, is that “sophisticated attacks no longer require sophisticated attackers”.

AI, it said, had closed the gap that once separated well-funded state operations from individual operators, and the same automated methods were now used by state services and lone actors alike.Automated espionage

The report described a Russian state-linked actor, tracked as GTG-20006, whose attribution Anthropic said was consistent with public reporting linking it to the group known as Midnight Blizzard.The actor attacked military-intelligence targets in Ukrainian and European governments, along with diplomatic and defence organisations and individuals connected to American foreign policy.The operation used AI to run much of the work, from building tools and infrastructure to phishing and data theft, the report said. AI agents monitored whether the actor’s malware had been detected by security products and, if it had, rebuilt the malware until it went undetected.Anthropic identified more than 20 organisations targeted in the actor’s operations, including government ministries, embassies, think tanks and defence firms, concentrated in Ukraine and Europe but extending to the Middle East and Asia.A majority of the operations in the report were run through AI by direct execution or orchestration, with humans setting targets and reviewing stolen data while the models carried out the steps in between.The report documented clusters of financially motivated activity by operators linked to the ShinyHunters group, known for large-scale data theft followed by pay-or-leak extortion.One French-speaking operator ran a credential-harvesting pipeline across a fleet of cloud servers that downloaded 1.8 million Android app files, decompiled them and scanned them for hardcoded passwords and keys, the report said.Stolen card records were sold through an online storefront that included cardholder details and a map of victims’ addresses.