23 Million Exchanges in Anthropic Misuse Report
Anthropic published its September 2026 threat intelligence report covering misuse cases disrupted between December 2025 and August 2026.
23 million exchanges attributed to Moonshot
Anthropic traced more than 23 million exchanges to Moonshot AI between May and July. The activity ran through a network of fraudulent accounts. Over one ten-day period Moonshot relayed almost 300,000 requests through 5,380 fraudulent accounts.
The company stated that Moonshot silently forwarded customer requests to Claude and displayed the responses as though they came from its own Kimi model. Anthropic's report noted one instance that exposed live credentials tied to a Russian defence agency. The same pattern appeared across seven China-based labs named in the document.
Alibaba generated more than 151 million exchanges across 3,500-plus accounts. Peak daily volume reached nearly 3 million exchanges to support training of Qwen models. Zhipu AI targeted Opus 4.6 for cyber reasoning across more than 3.4 million exchanges. Xiaomi replayed more than 400,000 developer sessions through 1,500 accounts. Proxy networks have become a standard extraction method.
TNW report provides the account details.
25 million SIM cards covered by Lakana 360
Anthropic assessed the subscriber to be a Bamako-based consultant working with Mali’s state intelligence service. The system monitored roughly 25 million national mobile SIM cards across all three operators in the country.
The system ran on local models on-premises, so account suspension left the deployed surveillance intact. It bypassed the legal requirement for a court order before operators could disclose certain records. One subscriber replaced what previously needed multiple analyst teams.
State-aligned actors and commercial spyware vendors used Claude to build surveillance systems between January and July. The cases spanned China, Iran and West Africa. Iranian units analyzed 155,216 tweets while producing open-source intelligence on US naval fleet positions. PRC security bureaus generated 2,475 investigative briefs in 30 days covering dissidents, Uyghurs in Syria, pro-democracy protests in Vancouver and Asian religious figures.
2 to 3 hour cloud compromises by single operators
Affiliates completed cloud compromises in as little as two to three hours. One operator used 10 AWS EC2 workers to process 1.8 million Android APKs while another extracted more than 2,100 Azure AD tokens across over 40 corporate tenants in 34 hours.
The report notes that a year earlier that work would have required teams of skilled people. Breaches now run in parallel by lone actors. Russian state espionage tracked as GTG-20006 engaged 24 of 27 targeted institutions over 130 days. The operation included Ukrainian ministries, defense bodies and drone supply-chain manufacturers. AI agents monitored deployed malware and recompiled code when it was detected. The labor barrier between state teams and individuals has narrowed sharply.
Continuous zero-day foundries run by China-based actors automated security appliance firmware analysis. They identified more than a dozen potential zero-day vulnerabilities in one month across roughly 50 global targets. AI supply chain attacks targeted 30 AI firms in four days while seeking pre-release models and production API keys.
151 million exchanges generated by Alibaba
Alibaba generated more than 151 million exchanges across 3,500-plus accounts. Peak daily volume reached nearly 3 million exchanges to support training of Qwen models. Source 3 lists the seven China-based labs involved in these operations, including Zhipu AI targeting Opus 4.6 for cyber reasoning across more than 3.4 million exchanges and Xiaomi replaying developer sessions.
Proxy networks have become a standard extraction method across multiple labs. Moonshot and DeepSeek proxied more than 23 million and 12.1 million exchanges respectively to Claude Opus. SenseTime obtained harvested user transcripts from data brokers. MiniMax operated an unbranded proxy to collect multi-turn developer prompts.
The report covers cyber operations, influence operations, surveillance, conventional weapons development, biological misuse, scams and fraud, and illicit distillation. It argues that static keyword blocking and isolated account suspensions are insufficient against distributed, multi-agent threats.
Threat Landscape Outlook
Anthropic points to architectural safeguards, stronger API identity controls, real-time threat sharing between model providers and verified trusted-access programs for high-risk scientific disciplines. The report highlights a lower cost of conducting large-scale cyber campaigns, surveillance operations and weapons-related engineering, while the broader AI supply chain is becoming both an attack surface and a source of computing resources.
Jacob Klein, who leads threat intelligence at Anthropic, told Axios that AI was making state surveillance cheaper and more efficient. It was not changing who governments target. “They’re effectively automating parts of the job within the intel apparatus,” he said. He added that the pattern was no longer theoretical. “Authoritarian states are using AI for surveillance, repression and influence operations today.”
My read: the documented shift to autonomous agent swarms changes the cost structure for every domain that has not yet published comparable figures.
No shared disclosure framework published yet
The report names seven harm areas and seven China-based labs but stops short of a joint protocol for real-time exchange of indicators across providers. No figure appears for the number of accounts still under review after the August 2026 cutoff. The sources also leave open how smaller labs without equivalent monitoring teams would detect equivalent activity on their own systems. The report withholds names of institutions, countries and specific biological agents in five cases, noting only that the individuals were working scientists and that older models such as Claude Opus 4 stayed below the threshold for meaningful assistance on gain-of-function research.
Keep reading
News
AI21 Labs Cuts 60% of Staff, Bets on Maestro
AI21 Labs slashes over 60% of staff, drops foundation models, and pivots to its Maestro agent optimization platform after Nebius acquisition talks collapse.
News
Alibaba Bans Claude Code Over Security Concerns
Alibaba told staff to remove Anthropic's Claude Code by July 10 over security concerns. Here's what triggered the ban and what it signals.
News
Anthropic Acquires Stainless: What It Means for AI
Anthropic bought Stainless, the SDK generator behind OpenAI and Cloudflare's client libraries. Here's the strategic play for AI agents.