Anthropic's September threat report: missile guidance, hotel WiFi spying and a Xiaomi data run
Anthropic's third threat-intelligence report says Claude wrote missile guidance software in Yemen and powered a Russian espionage campaign against 20+ targets.

Anthropic published its third threat-intelligence report on September 10. Titled "Detecting and countering misuse of AI: September 2026", the report ships with a PDF and an IOC CSV and covers activity it says it disrupted between December 2025 and August 2026 across seven harm areas, from cyber operations and influence operations to scams, biological misuse, conventional weapons development and distillation. Anthropic says Claude Haiku, Sonnet and Opus were used across the cases, and that no case involved Fable or Mythos-class models except one illicit distillation case.
What Anthropic says it found
Every row below is Anthropic's own account; none of it has been independently audited.
| Harm area | Case | Reported use of Claude |
|---|---|---|
| Conventional weapons | GTG-87001, northern Yemen | Wrote guidance, navigation and control software for three weapons programs |
| Cyber operations | GTG-20006, Russian espionage | Reconnaissance, planning and live operations against 20+ organizations |
| Distillation | Xiaomi | Replayed its own MiMo conversations and coding sessions to Claude at scale |
| Distillation | SenseTime | Bought Claude transcripts from third-party data vendors |
| Distillation | MiniMax | Built a proxy network offering only Anthropic and OpenAI models |
Yemen: a rocket, a ballistic missile and an "R2000" set
The Yemen case, tracked as GTG-87001, describes a cell of actors based in northern Yemen running three weapons development programs: "a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the 'R2000' set) that included a hypersonic glide vehicle variant." Anthropic says the group used Claude Code instead of human software engineers to write guidance, navigation and control software.
The Associated Press reported that the accounts were blocked and that the users did not succeed in "fielding an operational device" — though they did carry out a failed test of a guided rocket. Anthropic knows that because the users returned to Claude to ask why it failed.
Houthi political bureau member Hazam al-Assad told AP it is "unreasonable and illogical" that the group would rely on open sources to develop military capabilities. Trevor Ball of Armament Research Services told AP the Houthis "might be looking into hypersonic (missiles) by asking Claude" but have nowhere near the production or technical capability to build them — "U.S. hypersonic missiles are still in testing" — and already field Iranian-made anti-ship missiles whose guidance adjusts mid-course. Al Jazeera covered the claims the same day.
A Russian campaign and the collapsing cost gap
The cyber case, GTG-20006, is the one Anthropic frames as a trend. Its attribution is "consistent with public reporting linking the actor to Midnight Blizzard"; one operator used the handle "JackPoterz". More than 20 distinct organizations appear in the actor's planning, reconnaissance and live operations — government ministries, defense and intelligence bodies, embassies, think tanks and defense-industrial companies, concentrated in Ukraine and Europe, with some in the Middle East and Asia. The group bulk-exported the mailboxes of at least two drone component manufacturers and stole a complete proprietary drone vision software development kit.
To reach targets indirectly, it compromised at least three hospitality vendors running hotel guest WiFi and used admin credentials to modify DNS records so guest traffic — device identifier and IP — was sent to actor servers, then staged ClickFix malware lures; Microsoft described the technique in July 2026 as "CaptiveCrunch". Operators took over victims' WhatsApp accounts with headless browsers and the open-source WPPConnect library, suppressing read receipts while bulk-exporting conversations. The group also breached a North African government technology authority, exfiltrating more than 300,000 national identity records and the commercial registry data of more than half a million companies. A Microsoft 365 token-theft platform the report calls "Embassy Kit" pulled mail records from at least eight organizations including a national prosecutor office and a military education institute. Named malware includes PowerChrome, WUEngine, Shadow C2 and MiniPlasma on Windows, GiftDrop on Android and the DarkSword exploit chain on iOS.
Anthropic's stated trends: "AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators"; "sophistication has stopped being a reliable signal of who is behind an operation"; and "AI has inverted the cost back onto defenders."
Distillation: Xiaomi, SenseTime and MiniMax
The distillation section names three Chinese firms. Anthropic says Xiaomi ran an illicit distillation campaign, replaying conversations and coding sessions from its own MiMo models to Claude, often via OpenClaw and OpenCode harnesses. The report logs more than 400,000 exchanges over 20 days in March and April 2026 across more than 1,500 accounts routed through proxies, and suggests Xiaomi may have launched MiMo-V2-Pro with a free trial — later extended — intending to harvest data as the trial ended. Anthropic says the relayed traffic contained names, contact information and corporate data of hundreds of Xiaomi users in at least a dozen languages, and that it has no indication US persons' data was exposed. No comment from Xiaomi was available.
The same section says SenseTime bought Claude transcripts from third-party data vendors, and that MiniMax built a shell-company proxy network offering only Anthropic and OpenAI models.
What Anthropic says it changed
Anthropic lists three safeguards. Claude now summarizes its internal reasoning before responding, which the company says makes stolen transcripts less useful for training another model. Fable 5.1 introduced "preserved thinking", which stops new API accounts from altering the system prompt, tools or messages that precede Claude's reasoning. Accounts flagged for suspected abuse must verify their identity.
What the report does not establish
This is a vendor's self-report. Every case, attribution and "we disrupted it" claim originates with Anthropic, and no independent audit or third-party verification of the underlying evidence has been published. The document also doubles as positioning, arguing for Anthropic's safety posture and mitigation stack ahead of an IPO expected in October 2026. On the sharpest case, the only outside expert named in coverage doubts the capability the framing implies, and the accused party denies it.
Public reaction to the announcement post on X, which drew 49,038 likes and 11,272 reposts, focused less on weapons than on data. Top replies included @JC_OneNodeLab's "The report proves those AI labs can freely read all users' data." (5,397 likes), @anthonyronning's "Where's the report about how you've misused all of humanity's data for your own profits?" (3,658 likes) and @reey_ch's "So our data isn't really private as we thought?" (3,494 likes). A thread on r/singularity drew roughly 307 points.
Read against Anthropic's cyber-eval failures from the same week, the report's real contribution may be its admission that misuse detection now means reading customer transcripts at scale — the very thing its loudest readers objected to. Amodei's essay the same week cited these cases as a reason to slow down.


