AI

Anthropic Threat Report: Distillation, Bots, Stolen API Keys

Anthropic's September 2026 threat report: 151 million distilled exchanges linked to Alibaba, Russian espionage, an Istanbul-run election platform targeting Malaysia, and why API keys are now the prize.

Muhammet Fatih BatmanSeptember 12, 20264 min read7 views
Anthropic Threat Report: Distillation, Bots, Stolen API Keys

151 million. That is how many Claude exchanges Anthropic says one distillation campaign linked to Alibaba's Qwen lab pulled out of its models between May and July, through more than 3,500 fraudulent accounts, peaking at roughly 3 million a day. It is the largest single figure in the company's new threat intelligence report, "Detecting and Countering Misuse of AI: September 2026," published on September 10, and it is only one of nine operations the report describes. The others include a Russian state espionage group and a paid election-manipulation platform run out of Istanbul.

The report covers December 2025 to August 2026 and spans seven harm areas: cyber operations, surveillance, influence operations, conventional weapons, biological misuse, fraud, and illicit distillation. Anthropic's own framing is blunt: AI "has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators."

The distillation ledger

Distillation means harvesting a model's outputs to train another model. Anthropic's ledger, campaign by campaign: the Alibaba-linked operation at 151 million exchanges; a DeepSeek-linked operation that rerouted 12.1 million exchanges in 14 days; Moonshot AI relaying about 300,000 customer requests through 5,380 accounts in 10 days while users believed they were talking to Kimi. The capabilities being extracted were consistent: agentic behaviour and tool use, coding, data analysis, and logical reasoning.

The timing matters. Two days earlier, on September 8, the NSA, FBI and CISA issued a joint advisory naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI for "industrial-scale" distillation of US frontier models, including Claude, GPT, Gemini and Grok. Anthropic's report reads as the company-side evidence file for that advisory.

An influence-as-a-service shop in Istanbul

Case GTG-84005 is the one that made headlines in Southeast Asia. A platform marketed as a "military-grade, AI-driven, real-time political operations ecosystem" was traced to BBS Bilisim Teknolojileri, an Istanbul-based company. It orchestrated roughly 1,000 synthetic X accounts with "warm-up logic" to build credibility, fed real census and electoral data into Claude to profile every one of Malaysia's 222 parliamentary constituencies, and micro-targeted content along race, religion and royalty fault lines. A fake outlet, Malaysia Pulse, had Claude rewrite legitimate reporting under invented bylines, and the operators produced entirely fabricated dossiers against an opposition politician and civil society groups.

Claude refused parts of this. Anthropic says the model flagged one document as political defamation; the operators negotiated "sanitised wording" and carried on. The campaign was rated Category 2 on Anthropic's six-level reach scale, meaning content appeared on several platforms with no evidence it reached authentic communities.

Malware that rewrites itself faster than you can block it

The espionage case belongs to Midnight Blizzard, the Russian state-linked group. Targets included more than 20 government, military and diplomatic organisations in Ukraine and Europe, and a North African target that lost over 300,000 national identity records. Anthropic's phrase for the shift is that AI has "inverted the cost back onto defenders": when malware was detected, the model modified it faster than the defenders could respond. On the criminal side, one breach turned a stolen developer token into full cloud administrator access in about three hours.

Why your API key is now the target

The finding with the most direct business consequence is that the AI supply chain has become a deliberate criminal target. Several groups stole API keys and session tokens not from Anthropic but from its customers' environments. A Russian financial-crime group hit around 30 AI companies in four days, injecting malicious instructions into a vendor's evaluation sandbox to obtain production keys. A single French-speaking hacktivist ran an entire one-month campaign on stolen keys, breaching 14 of 42 tracked European political parties, media outlets and think tanks.

A stolen key delivers three things: resale value, compute billed to the victim, and cover, because the attack is attributed to the key's legitimate owner. Anthropic's recommendation is to treat AI keys and agent integrations with the same seriousness as production credentials, "because attackers treat them with the same level of seriousness, too."

Three things to do before Monday

First, inventory every AI key your organisation holds. In our own integration work we still find provider keys sitting in front-end code, shared .env files and chat threads; the report is the clearest statement yet that these are credentials, not configuration. Second, put spend caps and usage alerts on every key and rotate on a schedule, so a leak shows up as a billing anomaly within hours rather than at month end. Third, scope your agents: an agent that can read your CRM does not need write access to your cloud account. Across all nine cases the expensive part of an attack has become cheap; what still costs an attacker is a target that has done the basics.

Sources: Anthropic, Detecting and Countering Misuse of AI: September 2026, TechCrunch, The Decoder, Malaysiakini

Share This Article

Muhammet Fatih Batman

Written by

Muhammet Fatih Batman

Founder & Editor

Founder of YZ Uzman, with 20+ years of experience in web design and software development.

More news

Want to put this technology to work in your business?

Let's talk