Bioweapons, Espionage, Surveillance: Anthropic Reveals How Countries And Groups Misused Claude AI

0

Anthropic Reveals How Claude Was Misused For Bioweapons, Surveillance And Espionage

As artificial intelligence systems become increasingly capable, concerns over their potential misuse are also growing. Anthropic, the company behind Claude, has released a detailed safety report outlining several cases in which its AI models were allegedly misused for activities ranging from biological research and weapons development to surveillance, espionage, cyberattacks and influence operations.

The incidents documented by Anthropic occurred between December 2025 and August 2026. According to the company, the cases involved suspected state-backed actors, financially motivated criminals, propaganda networks, spyware operators and politically motivated groups.

The activity involved Claude Haiku, Sonnet and Opus models. Anthropic said the cases described in the report were not representative of ordinary misuse but instead reflected some of the most significant and novel threats it had identified.

Claude Misused In Sensitive Biological Research

Some of the most sensitive cases involved biological research. Anthropic said it encountered scientists, including some linked to state-supported programmes, whose work could potentially have legitimate scientific applications but also carried dual-use risks.

The company said biological research can occupy a difficult area where legitimate scientific work may overlap with research that could potentially contribute to the development of dangerous pathogens.

Jacob Klein, Anthropic’s head of threat intelligence, described the situation as highly nuanced, noting that malicious intent is not always obvious from a research request.

Anthropic identified five biological misuse cases. In one incident in May, a scientist sought assistance preparing a grant application involving gain-of-function research on chikungunya virus. The proposed work involved engineering mutations that could increase the virus’s harmful characteristics through repeated infection of live animals. Anthropic said it was particularly concerned because it believed the research was connected to a military research institute.

The company’s biological safety system blocked the request. However, Anthropic said the user subsequently attempted to bypass the restriction through a third-party platform, which later added another AI model as a fallback when Claude refused to provide the requested assistance.

In another case, a reseller relay reportedly allowed a user to prepare an orthopoxvirus immune-evasion grant application using Opus 5 in roughly an hour. Anthropic also described a separate researcher conducting planned avian influenza mammalian-adaptation experiments who was restricted to the company’s weakest model tier.

The company said it also disrupted two state-backed programmes involving venom or toxin redesign. During a 30-day review of state-linked activity, Anthropic identified about 35 separate research efforts. Most appeared to involve legitimate civilian science, although some had potential dual-use implications.

Anthropic said some users had circumvented restrictions designed to prevent access from countries where Claude was unavailable and had attempted to conceal the nature of their research. The company said it responded with account bans, hard refusals, weaker model access and proactive monitoring.

AI Used In Conventional Weapons Development

Anthropic said the misuse extended beyond biological research, with several groups attempting to use Claude to develop software associated with conventional weapons.

The company identified three cases in China, two in Russia and one in Yemen.

In Yemen, Anthropic said a group used Claude Code for work that would normally require human guidance, navigation and control engineers. The activity allegedly involved software for a guided rocket, a multistage ballistic missile designed to travel more than 2,000 kilometres and a variant of a hypersonic glide vehicle.

Anthropic said the group test-fired the guided rocket, although the field test appeared to have failed.

In Russia, the company identified a freelance operator associated with an effort known as DronDoc or Serafim. Anthropic said the operator used Claude Code to develop an autonomous first-person-view drone swarm. According to the report, the system could identify targets, including people, and trigger an attack without a human operator in the loop.

In China, Anthropic said an account potentially connected to the military-industrial sector used Claude to develop a 16-module electronic warfare and air-defence suppression system. The company said the activity later shifted from a generic simulation to scenarios involving 12 real targets in Taiwan, including a command bunker and air-defence systems.

China And Iran Linked To AI-Powered Surveillance

Anthropic also identified nine cases involving surveillance and profiling.

One operation allegedly linked to China used Claude to track, profile and recruit Uyghur individuals and journalists with connections to the Syrian Army. The company said the operation processed large volumes of WhatsApp and Telegram communications and used Claude for translation and role-playing designed to test deceptive approaches.

Anthropic also reported surveillance activity targeting Catholic cardinals, the Presbyterian Church in Taiwan, Tibetan Buddhists and Falun Gong practitioners.

In one instance, an actor reportedly continued prompting Claude after an initial refusal and obtained guidance related to suppressing activity involving 10 private citizens, along with intelligence about planned overseas protests.

Anthropic said it also identified two linked Iranian units operating 16 Claude accounts that claimed to have monitored or profiled 6,388 Iranians over a year. The activity allegedly included analysing 155,216 tweets to identify 39 opposition accounts and using a malicious Firefox extension to collect identities in a shared case-management system known as Arman.

The company also said an Iran-linked actor used Claude to identify US naval targets. Anthropic’s policies prohibit non-consensual surveillance and profiling.

Claude Used In Espionage And Cyber Operations

The report also highlighted cyber operations in which AI was allegedly used to automate reconnaissance, exploitation and monitoring.

Anthropic said one Russian-speaking actor used Claude in attacks against more than 20 Ukrainian and European government, defence and diplomatic organisations, as well as drone manufacturers.

According to the company, the actor obtained a drone vision-system software development kit, manipulated hotel Wi-Fi DNS records to distribute malware and compromised officials’ WhatsApp accounts. The operation also allegedly obtained more than 300,000 national identity records and over 500,000 company registry entries from a North African government organisation.

Anthropic said AI-powered monitoring systems could detect when security software identified the malware, after which the malicious code was automatically modified to evade detection.

The company said it banned the accounts involved, developed new behavioural detections and shared information with Microsoft, whose own reporting supported the findings related to the hotel Wi-Fi technique.

A separate China-linked group, which reportedly included two university students, allegedly used multiple AI workstreams for firmware reverse engineering, open-source intelligence gathering and scheduled intelligence collection. Anthropic said the operation compromised about 50 organisations worldwide.

AI Used To Generate Influence Campaigns

Anthropic also identified at least nine influence operations involving Russia, China, Iran, Bangladesh and Kenya.

The company said Claude was used both to plan influence campaigns and to generate misleading or false content. The operations achieved their widest reach when state-backed media organisations were used to distribute the material through television and radio.

One case involved Russian state-media personnel, including a former editor-in-chief of Sputnik Moldova, who allegedly used Claude as an editorial assistant to produce content.

Anthropic also described a Russian-speaking coordinator in Bangui who allegedly used Claude for Radio Lengo Songo, a Wagner-founded station. The company said the AI was used to produce pro-Russia and anti-France messaging, create forged Central African Republic government documents and prepare human-resources paperwork.

Anthropic said Claude refused one request to identify real individuals as militants for potential security action.

  • Criminal Groups Used Claude In Data Theft
  • Financially motivated criminals also appeared in Anthropic’s findings.

In one case linked to ShinyHunters affiliates, operators allegedly downloaded 1.8 million Android application packages and searched them for hardcoded credentials and other secrets. Anthropic said the information was connected to a Telegram-based carding operation.

The company also linked the activity to major data breaches involving more than 1TB of stolen information from a technology provider, tens of millions of airline passenger records and a software supply-chain compromise.

China-Based AI Dating Network Detected

Anthropic said it also uncovered a China-based network involving more than 20 dating applications marketed as being operated by real people but powered largely by Claude-generated personas.

The company said that during a two-week period in April 2026, it identified more than 4,700 AI personas, although another count in the report put the figure close to 5,000.

Those personas allegedly sent about 2.36 million messages to at least 25,000 real users. Anthropic said the network combined AI personas with human gig workers at roughly a three-to-one ratio and instructed the AI accounts not to disclose that they were automated.

  • The company said it subsequently banned the accounts and organisations involved.
  • Anthropic Accuses Rival AI Firms Of Illicit Distillation

Anthropic’s report also focused on another form of misuse: rival AI companies allegedly extracting Claude’s capabilities to train their own models.

The company described these activities as “illicit distillation” and named campaigns associated with Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax.

Anthropic said the largest campaign it measured was linked to Alibaba. According to the company, the operation reached nearly three million exchanges per day at its peak and generated more than 151 million exchanges between May and July 2026 through over 3,500 fraudulent accounts.

Moonshot AI allegedly forwarded around 300,000 customer requests to Claude over 10 days, while DeepSeek reportedly used a similar technique to generate 12.1 million exchanges over 14 days.

Anthropic said it responded by banning accounts, identifying proxy networks operating through resellers, strengthening systems designed to detect extraction attempts and requiring identity verification when accounts displayed suspicious behaviour.

Anthropic Warns AI Misuse Will Continue To Grow

Anthropic said it took action across all seven categories of harmful activity identified in the report. These measures included removing accounts, strengthening safeguards and sharing relevant intelligence with authorities, researchers, industry partners and affected organisations.

The company said it published the report because increasingly capable AI systems are likely to attract more sophisticated attempts at misuse.

Anthropic argued that understanding how malicious actors adapt AI tools can help developers, governments and security teams identify similar threats and strengthen collective defences as AI technology continues to advance.

Comments are closed.