Threat Intelligence
The Threat Intelligence team investigates real-world cases of misuse of Claude, and works with the broader Safeguards team to improve our defenses. To improve the safety and security of frontier AI models, we publish regular reports detailing the methods malicious actors use to exploit them.
What we learned mapping a year’s worth of AI-enabled cyber threats
As AI changes how cyberattacks happen, how well do the security community's frameworks hold up? A new report maps attacks onto MITRE ATT&CK.
Detecting and preventing distillation attacks
We have identified industrial-scale campaigns by three AI laboratories—DeepSeek, Moonshot, and MiniMax—to illicitly extract Claude’s capabilities to improve their own models.
Disrupting the first reported AI-orchestrated cyber espionage campaign
In September 2025, we detected and disrupted a highly sophisticated cyber espionage campaign. We’re sharing this case publicly to help others strengthen their own defenses.
Detecting and countering misuse of AI: August 2025
We’ve developed safeguards to prevent the misuse of our models, but malicious actors are actively attempting to find ways around them. Today, we’re releasing a report that details how.
Detecting and countering malicious uses of Claude: March 2025
This report outlines several case studies on how actors have misused our models, as well as the steps we have taken to detect and counter such misuse.
