ANALYSIS

Anthropic Says Adversaries Used Claude to Build Missile Software and Surveil 25 Million Phones

The Anthropic wordmark on a dark background, representing its September 2026 threat intelligence report
Anthropic's September report catalogs operations it says it detected and disrupted. Source: Anthropic
Quick answer: On September 10, 2026, Anthropic published "Detecting and countering misuse of AI: September 2026," a threat report describing operations it says it detected and disrupted between December 2025 and August 2026. The documented cases include a group in Yemen using Claude Code to build guided-rocket and long-range missile software, a surveillance system in Mali aimed at roughly 25 million mobile SIMs, an automated Russian intrusion campaign, a dating-fraud network running 4,700 fake personas, and seven Chinese labs using fraudulent accounts to harvest Claude outputs for training rivals. The significance is not any single case. It is that AI misuse has moved from a hypothetical the industry debated to a set of documented incidents a leading lab is now reporting on itself.
TLDR
Editor's note

The operations described here are Anthropic's own account, drawn from its published report and corroborated by Tier-1 coverage from Bloomberg and Al Jazeera. Several cases cannot be independently verified in their specifics, and Anthropic itself notes limits, saying, for the flagged biological-research accounts, that it "does not assert that they intended harm," and finding no evidence that the Yemen group fielded a working weapon. We have kept the claims attributed to Anthropic throughout and separated what the company documents from what it infers.

What Anthropic says it found

The report reads less like a policy paper than a case file. Anthropic frames it as a record of how abuse has changed since its 2025 reports, and its own summary is blunt about the intent behind the operations.

Our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity.
Anthropic, "Detecting and countering misuse of AI: September 2026"

The specifics are what give the sentence weight. In Yemen, Anthropic says a group used Claude Code in place of human software engineers, assigning different model instances to distinct roles while building guidance software for a guided rocket and a long-range ballistic missile. In Mali, it describes a surveillance system built for a state client and designed to target roughly 25 million SIMs, a system that stayed operational even after Anthropic cut the account's model access. A Russian operation tied to APT29 ran nearly its entire intrusion workflow through automated AI steps. A dating-fraud ring stood up 4,700 personas that exchanged 2.36 million messages with more than 25,000 targets inside two weeks.

Panel listing five operations Anthropic says it disrupted: Yemen weapons, guided-rocket and missile software; Mali espionage, surveillance of 25 million SIMs; Russia APT29 cyber, automated intrusion; a dating-fraud deception ring with 4,700 personas and 2.36 million messages; and seven Chinese labs harvesting Claude outputs for training
The operations Anthropic documents span weapons, espionage, cyber intrusion, mass deception, and model theft. Source: Santage; Anthropic, September 2026.

The through line is agentic, not conversational

Read together, the cases share a mechanism that earlier misuse did not. In each, Claude was not answering questions. It was doing the work, wired into an agentic pipeline where models plan, write code, and coordinate with one another. That is the shift the report is really documenting. When a small cell in Yemen can assign model instances the roles a missile-software team used to fill, the constraint that historically limited such work, access to scarce human expertise, weakens. The same logic runs through the surveillance build and the fraud ring, where automation let a handful of operators attempt a scale of activity that would once have needed a payroll.

The report by the numbers
25 millionmobile SIMs targeted by the Mali surveillance system, which kept running after model access was cut.
4,700fake personas in the dating-fraud ring, sending 2.36 million messages to 25,000-plus targets in two weeks.
7Chinese labs Anthropic names as using fraudulent accounts to harvest Claude outputs for training.
2missile systems, a guided rocket and a long-range ballistic missile, the Yemen group sought to build with Claude Code.

Why a lab reporting on itself is the story

The distillation finding connects directly to national-security concerns already in the open. Anthropic names seven Chinese labs it says used fraudulent accounts to pull Claude outputs for training, a claim that sits alongside recent reporting on how the NSA flagged six Chinese labs over distillation and how OpenAI and Anthropic joined 116 firms on shared cyber defense. What is new is the source. A frontier lab is publishing the ledger of how its own product was turned against the public interest.

That posture is not costless, which is what makes it notable. Anthropic has built its brand on being the careful lab, and it is moving toward a listing that would price that reputation. A report cataloguing missile software and mass surveillance built on Claude cuts against the marketing, and the company published it anyway. The generous reading is that transparency about abuse is the price of credibility on safety. The skeptical reading, voiced after the Coxon resignation days earlier, is that disclosure is easier than prevention, and that a deployed surveillance system surviving an access ban shows the limits of after-the-fact enforcement.

Source: @AnthropicAI

Both readings can be true at once. The report is a genuine contribution to public understanding and an admission of how little a model provider can control once its system is deployed downstream. The uncomfortable takeaway is the one the cases keep repeating: the barrier to serious misuse used to be talent, and agentic AI is lowering it. Anthropic has now documented that in its own logs. The harder question, which a threat report cannot answer, is what happens between detection and the next deployment that no one catches in time.

In short: Anthropic's September 2026 threat report documents Claude being used to build missile software in Yemen, to surveil 25 million SIMs in Mali, to run a Russian intrusion campaign and a 4,700-persona fraud ring, and by seven Chinese labs to harvest training data. The claims are Anthropic's, some unverifiable in detail, but the pattern is clear: agentic AI is lowering the skill floor for serious misuse, and a leading lab is now reporting it on itself.

Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.