Skip to content
← All Data Notes
Data Note · AI & Civil Society

Thirty-seven threat groups, and nothing to divide them by

Anthropic’s September 2026 threat report names 37 distinct threat groups disrupted between December 2025 and August 2026. Surveillance accounts for ten of them, more than cyber operations. The number is real, it is checkable, and it cannot be read as a measure of how much AI misuse there is — a limit the report states about itself in its third paragraph.

Investigation · ImpactMojo Data · 18 September 2026 · 7 min read · Source: Anthropic, Detecting and countering misuse of AI: September 2026
The finding

Counting the Generative Threat Group designators in the report gives 37 distinct groups across seven harm areas, each appearing in exactly one section. The largest is not cyber. It is surveillance, with ten — operations building tools to identify and monitor people, including dissidents.

What 37 cannot tell you is whether misuse is rising, falling or steady, because there is no denominator. The report selects its cases explicitly: they are “examples of the most notable and novel threat activity”, not a sample. A count of what one vendor found, judged interesting and chose to publish is a count of an editorial decision as much as of a phenomenon.

37
Distinct threat-group designators
10
In surveillance, the largest harm area
0
In biological misuse, which has 5 case studies
4
Pages given to scams and fraud, of 154
01 — What is actually in the report

Seven harm areas, eight months, 154 pages

The report covers activity disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, conventional weapons development, biological misuse, scams and fraud, and illicit distillation. It follows earlier reports in March, August and November 2025. Threat actors are given internal designators of the form GTG-NNNNN, and those designators are the only countable unit the report offers.

Counting them is mechanical and reproducible: extract every GTG- string, group by the section it falls in, take distinct values. No designator appears in two sections, so the seven counts sum to the total without double-counting.

Threat-group designators by harm area
Distinct GTG identifiers named in each section of the September 2026 report. Surveillance is the largest, ahead of cyber operations.
View the data
Harm areaThreat groupsPages
Surveillance operations1030
Influence operations940
Cyber operations737
Conventional weapons618
Illicit distillation412
Scams and fraud14
Biological misuse010
Total37151

Page spans are derived from the contents page; the seven sections plus a three-page overview account for all 154 pages. Counts are ImpactMojo’s, from the published PDF.

02 — The two columns do not track each other

Scams get one designator and four pages. Influence gets nine and forty.

Set the two columns side by side and they disagree. Cyber operations get the second-most pages (37) and the third-most designators (7). Scams and fraud get four pages and one designator, in a harm area that is almost certainly the highest-volume of the seven by number of victims — the report’s own overview leads with a network of fake dating apps built to defraud users.

Section length tracks how novel and narratively interesting a case is, which is what the report says it is selecting for. It does not track prevalence, and reading it as though it did is the mistake this note exists to prevent.

Biological misuse is the cleanest illustration. It has zero GTG designators and five case studies, described at length across ten pages. The cases are there; the designators are not. Any count of “threat groups” therefore reports zero for a harm area the report treats as among the most serious it covers.

03 — Why you cannot divide by anything

A numerator without a denominator is not a rate

To turn 37 into a rate you would need to know how many operations were attempted, or how many accounts were active, or how many were reviewed. None of those is published. The report is a set of case studies from an internal investigation process whose volume, thresholds and detection coverage are not described.

Three specific things follow, and they matter for anyone tempted to cite the figure as evidence of a trend:

Detection improves, which raises the count. The report describes strengthening safeguards after each case and sharing indicators with partners. Better detection produces more disruptions from the same underlying activity, so a rising count across successive reports is consistent with both more misuse and better detection, and the data cannot separate them.

The publisher is the subject. The organisation counting the misuse of its own product is also the organisation deciding which cases are notable enough to publish. That is not an accusation; it is a structural feature of vendor threat reporting generally, and it is the reason the numbers are a floor rather than an estimate.

Designators are an internal taxonomy. Whether one operation, one actor or one campaign gets one designator or three is an internal convention that is not defined in the report. Two counts made under different conventions are not comparable, including across the vendor’s own earlier reports.

04 — What it is good for

Read it as a typology, not as a measurement

Used as a catalogue of technique rather than a rate, the report is genuinely useful, and the surveillance section is the part that should concern civil society organisations in South Asia most directly.

Three patterns from that section, in the report’s own account. AI is being used in place of an engineering workforce: a single consultant working for Malian national security authorities used Claude to engineer a mass-interception platform covering all of the country’s mobile operators and generating dossiers on targets. AI is being used to ingest data in bulk to identify targets: one Iranian unit analysed hundreds of thousands of social media posts and selected 39 opposition accounts to monitor; actors in the PRC had content scored by political sensitivity and flagged for what they termed “control”. And the operational scale is being compressed — a PRC religious-affairs intelligence unit that once ran many teams of analysts is described as reduced to a single office producing thousands of investigations a month.

For an organisation working on rights, land, labour or minority issues in the region, the useful question is not how many threat groups there are. It is whether a well-resourced adversary now needs a team to do what one consultant with a model can do, and what that changes about how you handle a contributor list, a field diary or a complainant’s name.

How to read this responsibly

The count is ours, not the report’s. The report does not publish a total. We extracted every GTG-NNNNN string from the PDF text, assigned each to the section it appears in, and took distinct values. That method is stated so it can be checked and disagreed with.

Designators are not operations, actors or incidents. A designator identifies a group as the vendor tracks it. One group may run several operations; one operation may involve several groups. Counting designators counts the taxonomy, not the activity.

Zero does not mean absent. Biological misuse has no designators and five described case studies. The same applies anywhere else the report narrates a case without labelling the actor.

Page counts measure attention, not importance. They are included to show that the two columns diverge, not to rank harm areas. A four-page section is not a small problem.

This is one vendor, one window. Eight months, one company’s platform, one company’s detection. It says nothing about misuse of other models, about activity that was never detected, or about the periods before and after.

Sources & data
  • Anthropic, Detecting and countering misuse of AI: September 2026, published 10 September 2026. 154 pages. The seven harm areas, the case studies, the December 2025 to August 2026 window, and every GTG designator counted here.
  • The same report’s overview, for the selection statement quoted in section 03: the cases “aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date”.

Counts, page spans and all arithmetic are ImpactMojo’s, from the published PDF, and are shown in the data table in section 01. The extraction is a plain string match on GTG- followed by digits, grouped by section boundary.

Suggested citation

ImpactMojo Data (2026). “Thirty-seven threat groups, and nothing to divide them by.” ImpactMojo Data Notes. Retrieved from https://impactmojo.in/DataNotes/thirty-seven-threat-groups.html

Have a dataset worth digging into?

Data Notes are independent investigations built from public data. If you know a number that deserves a closer look, tell us.

Pitch a Data Note →