Anthropic reports seven AI abuse patterns observed Dec 2025‑Aug 2026
Anthropic released a threat‑intelligence report covering the eight‑month period from December 2025 to August 2026. The report catalogues seven distinct patterns of AI‑enabled abuse, ranging from cyberattacks and surveillance to fraud, weaponization, and unauthorized copying of AI capabilities.
Key points
- Anthropic's report identified seven AI abuse patterns from Dec 2025 to Aug 2026.
- A Russian‑speaker group used AI‑driven self‑repairing malware, targeting 20+ firms and stealing >300,000 personal records.
- Another criminal group scanned 1.8 million apps, extracting passwords and selling them via an online shop.
Two illustrative cases are highlighted. A Russian‑speaker attack group deployed AI‑monitored malware that automatically rebuilt itself when detected, allowing it to hit more than 20 organizations and, according to the report, steal over 300,000 citizens’ personal records from a single government agency. In a separate criminal operation, a group used ten cloud servers to automatically scan 1.8 million smartphone apps for hard‑coded passwords or access keys, then listed the harvested credentials for sale in an online shop. Both incidents relied on AI to perform repetitive work while human operators made high‑level targeting decisions.
The report argues that the traditional focus on attackers’ technical skill is giving way to an emphasis on intent, and it urges defenders to shift from merely adding countermeasures to accelerating damage containment and assessing who is targeting what.
What are the '7 Patterns of AI Abuse' detected by Anthropic? — Structural changes in cyber defense seen over 8 months
note.com · 19 September 2026
What are the '7 Patterns of AI Abuse' detected by Anthropic? — Structural changes in cyber defense seen over 8 months
When was the last time you reviewed your company's AI usage guidelines?
In many companies, the focus is likely on points of caution to ensure the company itself does not become a perpetrator, such as 'do not leak information' or 'do not input confidential data'.
However, reading the threat intelligence report published by Anthropic reveals another perspective that should be kept in mind. The perspective that the company's own AI usage is becoming an asset targeted from the outside. perspective.
In this article, we will break down in order: (1) the overall picture of the 7 abuse patterns published by Anthropic, (2) the case of a criminal group that investigated 1.8 million apps and malware that automatically repairs itself when detected, (3) the reason why the criteria for identifying attackers has shifted from 'technical capability' to 'intent', and (4) the two mindsets that the defense side should possess.
7 abuse patterns discovered by Anthropic
Anthropic, in its threat intelligence report, published the AI abuse cases detected and stopped during the 8 months from December 2025 to August 2026, categorized into 7 patterns.
Cyberattacks (unauthorized access/data theft)
Surveillance (tracking/profiling of individuals)
Public opinion manipulation (information manipulation via fake accounts)
Fraud/impersonation
Abuse for biological weapons
Abuse for weapons development
Unauthorized copying (other companies replicating AI capabilities without permission)
In this article, we will delve into two symbolic cases from '1. Cyberattacks,' which is the most familiar and potentially relevant to many companies among these.
Malware that repairs itself when detected
A symbolic example is the case of an attack group of Russian speakers.
Traditional cyber defense was a cat-and-mouse game where attackers created malware and defenders found it and implemented countermeasures. Every time defenders created a new countermeasure, attackers had to pay the cost of remaking their tools, which acted as a deterrent to attacks.
This group used a mechanism to have AI monitor whether their malware was being detected, and automatically remake and resend it whenever it was detected. This cycle continued without human intervention until it was no longer detected.
It is like a robot on a factory inspection line that fixes the design on the spot the moment a defective product is found and continues production. Even if inspections are increased, the effort on the production side hardly increases.
This group targeted over 20 organizations, and it is reported that they stole over 300,000 pieces of citizens' personal information from one government agency.
A group that automatically investigated 1.8 million apps
Another case involves a criminal group motivated by financial gain.
This group lined up 10 servers in the cloud and automatically downloaded and investigated as many as 1.8 million smartphone apps. They were mechanically checking to see if passwords or access keys had been left behind by developers who had inadvertently included them.
It is like hiding a spare house key under the doormat; while it may be convenient for the owner, if someone systematically goes around flipping over every mat in the neighborhood, they will find a large number of spare keys.
The keys found were automatically listed as products in their own online shop, which sold stolen credit card information and the like. Human intervention was almost non-existent.
The standard for identifying attackers is shifting from 'technical skill' to 'intent'
These two cases, which differ completely in purpose and organization, actually share a common point.
Both leave most of the tedious work to AI, while humans focus only on the most important decisions, such as 'what to target' and 'how to use what is stolen'—that is the point.
Just as when a factory production line is automated, a manager can mass-produce products by deciding only 'what to make' and 'where to sell it' without knowing the details of the machine operations, the same applies here. The internal workings of the line are the same whether it is state-sponsored or criminal; the only difference is why the manager is running the factory.
Advanced technical capabilities that were previously held only by state-level attackers have become accessible to individuals and small criminal groups through the use of AI. The premise that 'only a nation-state could carry out such an attack' has collapsed, andanalyzing the intent—'for whose benefit and what is being targeted'—has become more important—this is the biggest point running through the entire report.
Two mindsets that the defense side should have
Based on what we have covered so far, the mindset we should have boils down to a review of two premises.
The first is the recognition thatthe premise that 'increasing countermeasures raises the attacker's cost' has collapsed. As long as they can be recreated on the spot at machine speed even after being detected, simply piling on more countermeasures does not mean much. Rather, it becomes more important how quickly you can stop the damage after detection.
The second is todoubt the intuition that 'attacks that use a lot of AI are more dangerous'. Both cases we have looked at so far caused serious damage while leaving much to AI. Rather than the amount of AI usage itself, signs of 'who is targeting what' are better clues for measuring the scale of a threat.
When reviewing your company's AI usage guidelines, try adding one line not just about 'what not to input,' but also about 'how the company's own AI usage could be targeted.' Just doing that should change how you view the next threat report you read.
Another threat: 'unauthorized copying'
Finally, I would like to touch briefly on 'unauthorized copying (unauthorized distillation),' which was not covered this time among the seven patterns. This is not about harming customers or society, but rather an abuse of a different nature from the other six, whereAnthropic's own technical capabilities are being targeted. Just from the attacks of one Chinese AI company, up to 3 million interactions per day were recorded.
The structure of this unauthorized copying is also covered in detail in a past article.
▶︎ Read more: The 6 Chinese AI companies named by the US government—why did 'distillation' become an issue?
▶︎ Read more: What is a 'distillation attack'?—Explaining Anthropic vs. Alibaba from scratch
New book (released 7/27) "Claude: The Ultimate AI Automation Techniques": https://amzn.to/4eTUVG1
YouTube "Iketomo ch": https://www.youtube.com/@iketomoch
Podcast "Iketomo Obara Deep AI News": https://open.spotify.com/show/3hGAbKZI5oo9PsbFI1IxTr
This text was published by note.com and written by 池田朋弘(いけとも). It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.
More in Policy & Regulation
All →- Opinion: AI may pose existential risk yet some call for continued development · 1 src
- Australian treasury forecasts life expectancy near 90 and AI as defining influence · 1 src
- Microsoft exec calls AI scraping the largest theft of labor, internal filings show · 7 src
- Australian prime minister albanese discusses AI and child safety with apple exec tim cook · 1 src
- OpenAI releases framework to track AI model misalignment with six published cases · 1 src
Comments
via GitHub Discussions