Quick answer
On September 10, 2026, Anthropic published its report "Detecting and countering misuse of AI: September 2026". It covers malicious operations detected and disrupted between December 2025 and August 2026, across seven areas: cyber operations, influence operations, surveillance, scams, biological misuse, conventional weapons and distillation.
The report is long and sometimes chilling. We won't summarize all of it. This article focuses on what directly concerns a developer using Claude or another AI in their projects: attackers now treat AI API keys as production credentials. And you should too.
The big picture
Two trends stand out in the report's cyber section.
Sophisticated attacks no longer require sophisticated attackers. According to Anthropic, model capabilities have collapsed the labor and tooling gap that used to separate well-funded state operations from lone individuals. A hacktivist with stolen keys, scattered criminals and a state espionage operator all ran multi-victim campaigns that, a year earlier, would have needed many skilled operators.
AI's role is becoming autonomous. Most of the operations described used AI through direct execution or orchestration, with multi-agent frameworks handling reconnaissance, exploitation and exfiltration. Humans set targets and reviewed results.
All these operations used Haiku, Sonnet or Opus models. None involved Fable or Mythos, except one illicit distillation case.
The AI supply chain, a new target
This is the most useful part for developers. The report has a whole section titled "AI supply chain as target, loot, and attack compute". When an attacker gets hold of AI credentials, they gain three things at once:
- Loot: stolen keys and accounts resell on established markets.
- Compute: their attacks run at someone else's expense.
- Cover: the activity is attributed to the key's legitimate owner.
Picture someone stealing your company fuel card. The thief doesn't just fill up: they use it to haul stolen goods, and your name is on every receipt.
Concrete examples from the report
- A hacktivist campaign ran for a month entirely on stolen API keys.
- Affiliates of the ShinyHunters group, after grabbing a victim's AI keys, switched their own attacks onto those keys. One stolen key was used for about three weeks to attack other organizations.
- One operator in this group downloaded 1.8 million Android apps, decompiled them and scanned them with TruffleHog to find hardcoded secrets.
- A Russian-speaking group tracked as GTG-50020 compromised an AI vendor's evaluation sandbox and took its production keys first. A campaign run from the same infrastructure hit roughly thirty AI companies in about four days. Its stated goal, access to an unreleased Claude model, was never achieved, and Anthropic's systems weren't compromised: every key came from customer environments.
- Several actors compromised the LiteLLM implementation of AI wrapper services, using prompt injection to exfiltrate production API keys from their cloud containers.
The "cheap Claude" fake reseller
One case deserves its own mention. A group tracked as GTG-50021 offered discounted Claude access. In reality, customer traffic was silently proxied to a different model, while the installed tooling stole their Anthropic credentials to sell them to other resellers.
Anthropic's conclusion is unambiguous: AI access should only be bought through authorized channels, and a discount that requires routing your traffic and credentials through an unknown intermediary is a huge risk.
The line to remember
"Organizations should treat AI keys and agent integrations with the same level of seriousness as they do production credentials, because attackers treat them with the same level of seriousness, too." (from the report's AI supply chain section)
Where do keys leak?
The report lists the most common sources: legitimate customers who inadvertently exposed their API keys and session tokens in their products, applications and public code such as GitHub, mobile app install files, Docker containers, websites and chatbots. Malicious actors mine these sources constantly.
What you can do today
None of this is new, but the report gives it new urgency.
Hunt for your own leaks
Run a secret scanner over your repos, Docker images and mobile apps, exactly as an attacker would. If a key shows up in git history, it's compromised, even if you deleted it since.
Never ship a key client-side
An API key in a mobile app or a website's JavaScript is public. Go through a backend that holds the key.
Split and cap keys
One key per use and per environment, with spending caps. A stolen key then costs at most the cap.
Watch usage
An unexplained usage spike is often the first sign that someone else is using a key.
Harden your agent integrations
An agent that reads external content can be prompt-injected. Don't leave a production key reachable in its runtime environment unless it's needed.
If one of your keys has already leaked, our guide Leaked API key: what to do walks you through it.
The rest of the report in a few lines
The report covers much more. On the cyber side, it describes an espionage operation that Anthropic's attribution links to the publicly known group Midnight Blizzard, which automatically rebuilt its malware as soon as security products detected it. It also describes a group of students whose vulnerability research program produced several previously unknown flaws in a major security product.
It also details influence operations and illicit distillation, meaning industrial-scale extraction of a model's capabilities through fake accounts. Anthropic says it identified and disrupted distillation attacks from seven labs based in China.
In each case, Anthropic says it disrupted the activity, strengthened its safeguards and shared intelligence with authorities and partners where appropriate.
Next steps
- Leaked API key: what to do: the incident response procedure
- Don't give your API keys to Claude Code: limit exposure day to day
- CI/CD and cybersecurity: build secret detection into your pipelines
- Auto mode is now the default: what the classifier blocks to protect your secrets