Anthropic said its Claude AI model was used to automate cyberattacks and build a mass-surveillance system in Mali. The report shows how AI is lowering the cost of hacking and state surveillance for anyone with access to advanced models.
What actually happened
Anthropic disclosed the findings in a report published Thursday, 11 September 2026, according to Cointelegraph. A Russian-speaking operator identified as JackPoterz used customized AI-driven workflows to automate large parts of the attack chain. The operator targeted more than 20 organizations, including government ministries, intelligence bodies, embassies and diplomatic missions in Ukraine and Europe. Chinese-speaking operators used Claude as an engineering and orchestration layer for vulnerability research. One workflow produced more than a dozen possible zero-day findings in network-appliance firmware in one month. Anthropic said AI changes the economics of cyberattacks. Individual operators can now complete breaches in two to three hours and handle dozens of victims in parallel. Separately, a Bamako-based consultant working with Mali's state intelligence service used Claude as the primary engineering workforce. The consultant built a surveillance system monitoring roughly 25 million SIM cards across all three of Mali's national mobile operators.
How we got here
The report follows growing scrutiny of AI's role in offensive cybersecurity and state surveillance. Anthropic has flagged similar misuse before, and industry commentary has debated whether AI is fueling a wider 'hackpocalypse' in crypto and beyond, as referenced by Cointelegraph. Claude, like other frontier language models, is built for broad coding and reasoning tasks, which also makes it useful for automating exploit development and building surveillance software without specialized human expertise. This report marks one of the first detailed disclosures of state-linked actors using a commercial AI system as a core engineering layer for both offensive hacking and domestic surveillance.
Why this matters for you
For AI developers, the report signals that safety filters can still be bypassed by determined state-linked actors, raising pressure for stronger monitoring and export controls. For crypto and Web3 builders, faster AI-assisted breaches mean smart contracts, exchanges and wallets face compressed windows to detect and respond to attacks. For everyday users, the Mali case shows AI can enable mass surveillance without a court order, a warning for anyone in jurisdictions with weak legal oversight. For AR and wearable hardware makers, the episode is a reminder that always-on, AI-connected devices will need built-in safeguards against misuse from the start.
The bigger question
If a single AI model can automate both cyberattacks and mass surveillance, who is responsible when it is misused, the company that built the model, the operator who deployed it, or the government that commissioned it? That question has no settled answer yet, and it will only grow more urgent as AI tools become cheaper and more capable.
What to watch
Anthropic has not announced further disclosures beyond the 11 September 2026 report. Expect continued scrutiny of AI misuse in cybersecurity and surveillance, alongside related developments like Nvidia's $12.9 billion (USD) acquisition of Hugging Face on 3 September 2026. For bonuz readers tracking AR and smart glasses, this case underlines why on-device AI safeguards will matter as wearable hardware becomes more autonomous.



