Anthropic published its September 2026 threat intelligence report this month, a document that reads less like a corporate safety disclosure and more like a field guide to everything Claude has been quietly recruited to do while nobody was watching — which is, it turns out, rather a lot. The header case involves a freelance technical consultant in Bamako who spent the first half of this year building "Lakana 360" for Mali's junta-run intelligence service, ANSE. It is a surveillance platform capable of tracking roughly twenty-five million SIM cards, which is to say, functionally, the entire population of Mali plus a healthy margin for error. It can pull calls, texts, and voice traffic. It can re-identify a target by voice alone if they swap SIM cards to dodge it. It can flag who's using a VPN. Anthropic banned the consultant's account in July. The system he built keeps running, because it runs on ANSE's own servers, and a banned account is not the same thing as an unplugged one.
Thirty Days, No Human Required
The Mali case was the most viscerally uncomfortable entry, but hardly the only one. A Russian state operation Anthropic tracks as GTG-20006 — overlapping with the group known elsewhere as Midnight Blizzard — spent 130 days running largely autonomous attack chains against Ukrainian ministries, European defense bodies, and drone supply-chain manufacturers, making off with more than 300,000 national identity records and half a million company registry entries from a North African government along the way. Its most notable trick wasn't the theft; it was the maintenance. The operators used Claude to monitor which of their own malware families — tools with names like PowerChrome and Shadow C2 — antivirus vendors had started catching, and then had the model autonomously rewrite the tools to evade detection again. The defenders patched. The malware noticed, and fixed itself. This is, structurally, the exact opposite of how the cybersecurity arms race is supposed to work.
Meanwhile, In the Content Mines
Elsewhere in the report, a France-based advertising agency was caught running roughly seventy fabricated news websites in twenty languages, backstopped by seventy matching social accounts and more than 250 fake commenters, collectively publishing over 8,913 articles — many of them legitimate journalism quietly rewritten with a political slant — aimed at six continents. A separate Istanbul-based outfit marketed itself, without apparent embarrassment, as a "military-grade, AI-driven, real-time political operations ecosystem," and used it to manage a thousand fake accounts and manufacture false allegations against opposition candidates ahead of Malaysian elections, requesting engagement numbers in the millions to make the whole apparatus look organic. Separately, Chinese university students in Hunan reportedly used Claude in a semi-automated loop to discover more than a dozen new vulnerabilities in security appliances in a single month, then went looking for roughly fifty organizations to try them on.
The Part Where Everyone Issues a Statement
Anthropic's own framing is that this is what responsible disclosure looks like: find the misuse, ban the accounts, publish the details, let the rest of the industry calibrate accordingly. That is, genuinely, more transparency than most AI labs manage. It is also an answer to a question nobody quite wants asked aloud, which is what happens when the banned account was never the bottleneck to begin with. Mali's surveillance platform does not need a Claude API key to keep watching twenty-five million phones tonight. It needed one, once, to get built. The receipt survives; the thing it built for does not require a subscription.
Sources: Anthropic — Countering misuse of AI: September 2026 · Bangkok Post — Weapons, spyware and AI scams: Anthropic exposes Claude misuse · Yellow — Anthropic Finds Malicious Actors Used Claude To Target 20+ Organizations And Monitor 25M SIMs



