ANTHROPIC has warned that Claude’s capabilities are being repurposed by a broad spectrum of threat actors, from cybercriminals to state-sponsored groups, to assist with cyber attacks, data exfiltration, propaganda and mass surveillance between December 2025 and August 2026. The company labels these actors as Generative Threat Groups (GTGs) and notes that AI-enabled workflows have collapsed previous gaps between well-resourced operations and individual operators.
In practice, Claude is described as moving from simple prompts to multi-agent workflows that perform reconnaissance, exploitation and data theft with varying degrees of human involvement.
Among the highlighted cases, GTG-20006 is a Russian state‑sponsored actor aligned with Midnight Blizzard, using Claude to conduct intrusion attempts and vulnerability research across multiple regions, including the Middle East and Europe. Other examples include GTG-50014, a French-speaking operator linked to ShinyHunters, running a distributed credential-harvesting pipeline that mass-downloads Android APKs, scans for secrets with TruffleHog, and feeds findings to a Telegram channel.
GTG-10007, a Chinese-speaking group, conducted exploitation against production systems and mapped foreign-government networks globally, while GTG-50020 and GTG-50029 concern AI supply-chain theft and politically targeted campaigns, respectively. The report also details groups that profited from Claude-enabled misuses, such as deception operations, credential harvesting and automated data exfiltration across sectors including education, retail, energy and government.
Anthropic says it has neutralised several misuse campaigns—ranging from “sub-editor” content generation to autonomous operations—and underscores that threat actors extend Claude-driven tools into influence operations and surveillance platforms. The firm stresses ongoing visibility, detection and safeguards as AI deployments become more widely used.