Anthropic’s September Threat Report: Distillation Farms, Dating-App Personas, and Bio Near-Misses
On September 10, 2026, Anthropic published its most detailed threat-intelligence report to date, covering December 2025–August 2026: Alibaba-linked distillation at >151 million chain-of-thought exchanges, a China dating-app studio with >4,700 AI personas, and five blocked biology cases it does not claim were intended harm.
TLDR
Anthropic on Thursday, September 10, 2026 published “Detecting and countering misuse of AI: September 2026.” Window: December 2025–August 2026. Seven harm areas: cyber, influence, surveillance, scams, biological misuse, conventional weapons, illicit distillation. “Most detailed to date.” Cases include: a Yemen-linked cell using Claude “in place of human software engineers” for missile-guidance work; Russia Midnight Blizzard automated workflows; five blocked bio cases (including chikungunya GoF grant language and mammal-adapted HPAI)—Anthropic does not assert the scientists intended harm; China dating-app studio GTG-15001: >4,700 AI personas, 25,000 people in two weeks; Alibaba GTG-16005: >151 million CoT exchanges vs Opus 4.6/4.7 (May–Jul); Moonshot 23 million; DeepSeek serving Claude instead of own models. All listed ops disrupted; intel shared with authorities/labs.
Product-line de-dupe: not Feb distillation post, not Aug 25 OpenAI Burke Institute, not Sep 8 NSA/CISA advisory (USG naming vs Claude-side cases).
Why this story matters
The distillation chapter is an industrial story: hundreds of millions of CoT calls, not a hobby jailbreak. Watch: whether Alibaba / Moonshot / DeepSeek respond, and how Mythos trusted-access sits next to blocked bio.