Anthropic’s Claude misuse report reveals spying, weapons

Anthropic published a new Claude misuse report on 10 September, laying out how people tried to turn its AI models toward hacking, state surveillance, weapons development and biological research. The company said it caught each operation and shut it down before the activity caused lasting harm.

The report covers cases that Anthropic’s Threat Intelligence team disrupted between December 2025 and August 2026. It spans seven harm areas: cyber operations, influence operations, surveillance, conventional weapons development, biological misuse, scams and fraud, and illicit distillation. The misuse involved Claude’s Haiku, Sonnet and Opus models. Anthropic said its Fable and Mythos-class models appeared in only one distillation case. In every instance, the company banned the accounts, strengthened its safeguards and shared intelligence with authorities and industry partners where appropriate.

What the Claude misuse report found about cyberattacks

The largest section of the report covers cyber operations. Anthropic’s central claim is that AI has narrowed the gap between well-funded state hackers and lone operators. The company pointed to a hacktivist using stolen API keys, financially motivated individuals, and a state espionage group, each running multi-victim campaigns that once needed a full team of skilled engineers. Anthropic reported breaches completed in two to three hours, with a single operator handling dozens of victims in parallel.

One case, tracked internally as GTG-20006, involved a Russian-speaking operator running espionage against Ukrainian and European government targets, including diplomatic and defence organisations. Anthropic attributed the activity, in line with public reporting, to the group known as Midnight Blizzard. The actor used Claude to check whether security software had flagged its malware, then automatically rebuilt the code to slip past detection.

A separate operation traced back to two undergraduate students in Hunan, China, who ran what Anthropic called agent swarms against roughly fifty organisations. One target was a Southeast Asian government agency, from which the actor retrieved citizen records.

A surveillance platform built by one consultant

Anthropic said state-aligned actors and commercial spyware vendors used Claude to build surveillance systems between January and July, in cases spanning China, Iran and West Africa. The company called one case the most striking: a single subscriber used Claude as an engineering workforce to build a platform named Lakana 360.

Anthropic assessed the subscriber to be a Bamako-based consultant working with Mali’s state intelligence service. The system monitored roughly 25 million SIM cards across all three of the country’s mobile operators, and it bypassed a legal requirement for a court order before an operator could disclose certain records. It also ran on local models on-premises, so banning the Claude account did not affect the deployed system.

Other cases named Iranian actors deploying a malicious Firefox extension that harvested identities from social networks, and a Chinese religious affairs intelligence unit that had shrunk from several teams of analysts to a single office. That office now produces thousands of investigations a month with an AI assistant. In another Chinese case, Anthropic said Claude scored social media posts by political sensitivity and flagged people for what the operators termed control.

Jacob Klein, who leads threat intelligence at Anthropic, told Axios that AI is making state surveillance cheaper and more efficient without changing who governments target. “They’re effectively automating parts of the job within the intel apparatus,” he said. He added that the pattern is no longer theoretical: “Authoritarian states are using AI for surveillance, repression and influence operations today.”

A new category: weapons development

The report documents what Anthropic described as a new form of misuse: using Claude to write software for conventional weapons. It detailed six cases, three in China, two in Russia and one in Yemen.

In the Yemen case, a cell in the north of the country ran three weapons programmes, including a guided rocket, a multi-stage ballistic missile with a stated range goal above 2,000 kilometres, and a set of missile variants that included a hypersonic glide vehicle. Anthropic said the actors used Claude Code in place of software engineers to develop guidance and control code, and that they test-fired a guided rocket in a launch that appears to have failed. The Russian cases involved freelance actors working on an autonomous kamikaze drone swarm.

Biological research and hard judgment calls

Anthropic presented five cases where people used its models in ways that could support biological weapons development, and it stressed how difficult those judgments are to make. The company withheld the names of the institutions, the countries and the specific biological agents involved, and said the individuals were working scientists rather than people with clear intent to cause harm.

In one example from May, a request for help writing a grant application involved gain-of-function research on the chikungunya virus, work intended for a military research institute. “You are not seeing someone in a comic book kind of way say, ‘Hey, I want to build a biological weapon to kill everybody,'” Klein told The New York Times. “It’s an incredibly nuanced situation.” He told the paper that Anthropic did not know whether the research was meant to be weaponised, but that a military institution running gain-of-function work was concerning on its own. Anthropic said older models such as Claude Opus 4 sat well below the level needed to meaningfully assist such work, and that it has since launched newer models with stronger safeguards.

Chinese labs accused of distillation

The report also expands on illicit distillation, which Anthropic defines as covertly extracting a model’s capabilities to train a rival system. The company said it identified campaigns from seven China-based labs, all targeting its generally available models rather than Mythos.

Anthropic named Moonshot AI, which it said silently forwarded customer requests to Claude and displayed the responses as though they came from its own Kimi model. Over one ten-day period, Anthropic said Moonshot relayed almost 300,000 requests through a network of 5,380 fraudulent accounts, and it attributed more than 23 million exchanges to Moonshot between May and July. The company made similar allegations against DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax. Some of the relayed queries exposed sensitive user data, Anthropic said, including in one instance live credentials tied to a Russian defence agency.

The distillation findings arrive alongside a US intelligence advisory naming six Chinese firms, which Beijing has rejected. Anthropic said most of the influence operations it caught drew little or no authentic engagement before it disrupted them, a caveat other AI platforms have made in similar reports. The company said it published the Claude misuse report because it has an obligation to disclose the activity and to give governments and civil society a clearer view of how these threats take shape in practice.