BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

Anthropic Finds Malicious Actors Used Claude To Target 20+ Organizations And Monitor 25M SIMs

Anthropic says Claude was used in cyber campaigns targeting more than 20 organizations and to engineer a Mali surveillance system monitoring roughly 25 million SIM cards. Key Points: Anthropi

AnonymousCryptoCompass newsroom
September 11, 2026
2 min read
NEWS
Anthropic Finds Malicious Actors Used Claude To Target 20+ Organizations And Monitor 25M SIMs
CryptoCompass editorial visual for policy coverage.

Anthropic says Claude was used in cyber campaigns targeting more than 20 organizations and to engineer a Mali surveillance system monitoring roughly 25 million SIM cards.

Key Points:

  • Anthropic said a Russian-speaking operator used Claude-driven workflows across espionage operations targeting more than 20 organizations.
  • Chinese-speaking operators used Claude for automated vulnerability research that produced more than a dozen possible zero-day findings in one month.
  • A Mali consultant used Claude to help build surveillance covering roughly 25 million SIM cards.

Claude Cyberattacks

Anthropic said in its September threat intelligence report that a Russian-speaking operator using the handle “JackPoterz” relied on customized AI workflows to automate much of an espionage campaign. The campaign centered on Ukraine and Europe.

The operator targeted government ministries, defense and intelligence bodies, embassies, diplomatic missions, think tanks and defense companies, while also reaching targets in other regions. Claude assisted across the attack chain.

Anthropic also identified Chinese-speaking operators who used Claude as an engineering and orchestration layer for offensive cyber work, including vulnerability research against security products and network appliances.

One continuously running workflow generated more than a dozen possible zero-day findings in a single month, while parallel systems handled reconnaissance, malware development and intelligence collection.

Also Read:OpenAI's Two-Week Freeze Passed, Then Altman Floated Pacing With Rivals

Anthropic Risk Warning

The company said the cases show how AI can reduce the labor and expertise required for sophisticated attacks, allowing individuals or small groups to run operations that once needed larger teams. Some breaches took only two to three hours.

A second case centered on domestic surveillance in Mali. Anthropic said a likely Bamako-based independent consultant working with Mali’s state intelligence service, ANSE, used Claude as the primary engineering workforce for “Lakana 360,” which monitored roughly 25 million SIM cards.

The platform ran on local infrastructure and models. Claude provided software design and engineering support for a system that Anthropic said could collect call records, text messages and voice traffic while generating intelligence dossiers without requiring users to provide a court order.

Anthropic banned the account and added detections aimed at preventing similar misuse, although the company said those actions did not disable the locally deployed surveillance platform. The September report follows Anthropic’s earlier threat intelligence disclosures from Mar., August and November 2025, documenting a shift from chatbot assistance toward increasingly automated cyber operations.

Read Next:Apple iPhone Duo Faces Two Early Demand Risks At $1,999