Latest News

Anthropic Says China- and Russia-Linked Actors Used Claude…

Anthropic says China- and Russia-linked actors were among groups attempting to use its Claude AI models for cyberattacks, surveillance and weapons-related work, revealing how rapidly artificial intelligence is being integrated into state security and criminal operations.

The findings appear in Anthropic’s September threat-intelligence report, covering activity the company identified and disrupted between December 2025 and August 2026. The cases span seven categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and illicit model distillation.

Anthropic emphasized that the incidents represent particularly notable examples rather than typical Claude usage. The company says it terminated the relevant accounts, strengthened safeguards and shared intelligence with authorities and industry partners where appropriate.

AI Agents Execute Larger Parts of Attacks

One of the most significant cases involved hackers whose techniques Anthropic said were consistent with Midnight Blizzard, a Russia-linked espionage group previously attributed by the U.S. government to Russia’s SVR foreign intelligence service. The operators targeted more than 20 organizations associated with Ukrainian government, military and diplomatic interests.

Claude was allegedly used across phishing operations, hotel Wi-Fi compromises and WhatsApp account takeovers. Anthropic said the attackers also developed an automated system capable of detecting when malware was identified by security software and repeatedly rewriting the code until it could evade detection.

The significance was the degree of automation. Rather than simply asking an AI chatbot for code or advice, attackers increasingly deployed multi-agent systems capable of performing substantial portions of an operation while humans acted primarily as supervisors.

Anthropic separately identified ShinyHunters-affiliated cybercriminal activity and a Chinese undergraduate team using Claude to automate vulnerability discovery and exploitation. The company argues AI is reducing the technical expertise and manpower historically required for sophisticated cyber operations.

Surveillance and Weapons Work Expand Risks

Claude was also used in surveillance operations. Anthropic identified three accounts it associated with Chinese municipal security services that allegedly used the models to profile overseas activists and organizations as part of surveillance and transnational-repression efforts.

Government-linked actors in Iran and Mali were also identified using Claude to collect information, analyze subjects and help select surveillance targets. Weapons-related cases extended across China, Russia and Yemen. Anthropic said operators attempted to use Claude to develop software supporting conventional weapons including missiles, armed drones, firearms, bombs and associated targeting and control systems.

Other cases involved intelligence gathering and procurement connected with weapons programs. Influence operations formed another category. Anthropic reported Russia-linked efforts to generate propaganda presented as independent journalism, including fabricated narratives concerning Moldova’s elections. It also identified Iranian state-aligned accounts producing and distributing political content across social-media platforms.

The report comes as Anthropic simultaneously accuses several Chinese AI companies of attempting to extract Claude’s capabilities. It says Alibaba-linked operators generated more than 151 million Claude interactions between May and July using over 3,500 fraudulent accounts, while Moonshot and DeepSeek allegedly routed millions of customer requests through Claude.

Those distillation allegations are separate from the state-linked malicious-use cases and should not be conflated with them. Anthropic’s findings also have an important limitation: they describe activity visible through its own systems and reflect the company’s attribution assessments.

They do not establish that Claude independently conceived or initiated the operations. Instead, the report documents humans deliberately attempting to use AI as infrastructure for activities they were already pursuing. What has changed is the amount of work AI can perform.

Anthropic says models are increasingly moving from answering questions to coordinating reconnaissance, coding, analysis and execution. That shift could make sophisticated cyber operations, surveillance and weapons development cheaper and faster—while reducing the number of skilled humans required to carry them out.

You may also like