Skip to content

How Anthropic Says Claude Was Used for Weapons, Spying and Cyber Operations

Getting your Trinity Audio player ready...

How Anthropic Says Claude Was Used for Weapons, Spying and Cyber Operations

Anthropic published its latest threat intelligence report on September 10, disclosing a wide range of cases in which state-linked groups, cybercriminals, spyware vendors and other bad actors attempted to weaponize its Claude AI models for activity spanning cyberattacks, espionage, weapons development, mass surveillance, fraud and biological research with potential weapons applications. The report, titled “Detecting and Countering Misuse of AI: September 2026,” is the company’s fourth such disclosure following earlier reports in March, August and November of 2025, and covers activity Anthropic says it identified and shut down between December 2025 and August 2026.

Anthropic organized the roughly eight months of findings into seven categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit model distillation. According to the company, all of the documented misuse involved its Claude Haiku, Sonnet and Opus models, with only a single distillation case involving its newer Fable or Mythos-class models, which Anthropic says carry additional safeguards specifically designed to limit their usefulness for harmful cyber tasks.

Among the most striking cases described in the report is one involving a China-based actor that Anthropic says used Claude to help build an electronic-warfare and air-defense suppression software suite capable of ranking potential targets and modeling radar jamming. Anthropic reported that during the course of the project, the actor modified a simulation to include a list of 12 specific targets in Taiwan, among them early-warning radar installations, Patriot and Tien Kung missile batteries, air bases, and a command bunker. Separately, the report describes Claude being used in connection with autonomous drone-swarm development tied to Russian actors, alongside a broader state-level cyber-espionage campaign that Anthropic says involved exploit research, malware creation, surveillance tooling, and mass-targeting operations. One cluster tracked internally by Anthropic under the identifier GTG-20006 reportedly automated an entire Russian espionage workflow, from initial tool development through to data exfiltration, while another cluster labeled GTG-10007, tied to a Chinese exploit-development operation, ran coordinated agent swarms conducting reconnaissance in parallel and reportedly surfaced more than a dozen potential zero-day vulnerabilities within a single month.

Pay Attention:  Boston Scientific Says Cyberattack Likely to Hurt 2026 Sales, Profit as Company Now Expects to Miss Full-Year Guidance

On the biological research front, Anthropic disclosed five cases involving work it says could plausibly support biological weapons development, including gain-of-function research, experiments involving influenza adaptation, work on immune evasion in orthopoxviruses, toxin optimization, and computational redesign of existing toxins. Anthropic was explicit in the report that identifying these cases does not establish that any biological weapon was actually produced as a result, framing the disclosures as evidence of concerning research directions rather than confirmed weapons outcomes.

The surveillance category covers a separate thread of cases in which Anthropic says state-aligned actors, state-linked contractors and commercial spyware vendors used Claude between January and July 2026 to help build and operate surveillance systems, part of what the company describes as a broader trend of AI tools being used to assist with monitoring and tracking operations that would previously have required more specialized technical expertise. On the influence operations side, one cluster identified as GTG-54002 reportedly published at least 8,913 articles across roughly 20 languages spread over 70 fake news websites, supported by a network of more than 250 inauthentic commenting accounts designed to make the content appear more organically discussed than it actually was.

Perhaps the largest single case by volume involved illicit model distillation, a practice where one company attempts to extract or replicate another company’s model capabilities through large-scale automated querying. Anthropic described a case tied to Alibaba as the largest distillation attack the company says it has ever measured, involving more than 151 million exchanges with Claude between May and July 2026, activity some outside analysts have connected to capability improvements later announced in Zhipu’s GLM-5.3 model.

Pay Attention:  Crypto Platforms Have Lost Over $3.63 Billion to Cyberattacks, Even Though Most of Them Passed Security Audits

Reuters, which reviewed the report ahead of publication, noted that the threat actors named across these cases span at least ten countries, with clusters tied to China, Russia, Iran and other regions cited repeatedly throughout the document, though Anthropic’s report notably does not point to any case originating from within the United States despite the country being a frequent target of the disrupted operations. Anthropic has been careful throughout the report to frame these cases as instances of humans directing Claude toward malicious ends, rather than any indication that its models independently decided to pursue espionage, surveillance or weapons-related work on their own. The company describes the pattern running through many of the cyber cases as increasingly agentic, where an operator hands the model a general objective and lets it independently survey a target environment, write and execute scripts, summarize what it finds, and repeat the process with minimal human intervention along the way, a workflow that has been informally nicknamed “vibe hacking” in some of the surrounding technical commentary.

In each case documented in the report, Anthropic said it disrupted the activity by banning associated accounts and deploying updated detection classifiers, while also sharing relevant intelligence with government authorities and industry partners where the activity extended beyond its own platform. The company acknowledged, however, that determined actors have continued adapting around its defenses using tactics like VPNs, fraudulent identity verification during account setup, third-party resellers, and stolen API keys or session tokens, with access to frontier AI models themselves increasingly becoming something criminals steal and resell rather than something they need to obtain through legitimate channels.

Pay Attention:  Boards Prepare for Digital Infrastructure Shocks Amid Rising Cyber Risk, Capgemini Survey Finds

Anthropic has framed the report as an effort at transparency intended to help other AI developers recognize similar misuse patterns on their own platforms and to give governments, researchers and the broader security community a clearer picture of how these threats are evolving as AI systems become more capable and more widely deployed. The full report, including detailed case studies and the specific threat actor identifiers referenced throughout, is available directly through Anthropic’s published threat intelligence report.

Leave a Comment