Anthropic's New Threat Report Reveals How Attackers Are Using Claude to Conduct Bioweapon Research
Anthropic has disclosed that it disrupted several coordinated attempts by malicious actors to use its Claude AI models for dangerous biological research, including gain-of-function experiments designed to make viruses more transmissible and lethal. The company's latest threat intelligence report, published on September 11, 2026, details how attackers across seven distinct harm categories exploited Claude between December 2025 and August 2026, marking an escalation in the types of misuse frontier AI systems now face.
What Specific Bioweapon Research Did Attackers Attempt?
Among the most alarming cases documented in Anthropic's report were five instances where unnamed actors attempted to use Claude for biological research that could facilitate weapons development. In one particularly concerning case, dozens of users requested Claude's help authoring a grant application for scientific funding that involved gain-of-function research on the chikungunya virus, a mosquito-borne pathogen that causes severe pain and fever in humans.
The grant proposal specifically sought to enhance the virus's transmissibility and immune evasion properties, according to Anthropic's report. While such research could theoretically support vaccine and treatment development, the company emphasized that it could equally be weaponized to make the pathogen more dangerous. Another case involved actors requesting assistance with research on "avian influenza mammalian-adaptation experiments," which could enable the virus to jump between species more easily.
Notably, all five bioweapon-related cases involved Claude's older models, such as Claude Opus 4 and Claude Sonnet 4.5 from 2025. Anthropic stated that these earlier versions "were well below the threshold where they could meaningfully assist a sophisticated user in carrying out dangerous biological research." However, the company acknowledged that its newer Claude Fable and Mythos-class models represent a qualitative leap in capability, prompting the deployment of stronger safeguards.
Anthropic
How Is AI Enabling Individual Hackers to Conduct State-Level Cyberattacks?
Beyond bioweapon research, Anthropic's report reveals a troubling shift in the cybersecurity landscape: individual hackers are now sustaining sophisticated cyberattack campaigns that would have required teams of skilled operators just a year ago. The company documented cases where AI models compressed the labor and expertise gap that traditionally separated lone attackers from state-sponsored groups.
In one case involving the ShinyHunters extortion collective, attackers progressed from stealing a single developer token to gaining full administrative control of a victim's cloud environment in approximately three hours. In another incident, AI agents performed nearly all the work of extracting more than 2,100 Azure Active Directory token sets from over 40 corporate tenants in about 34 hours, according to Anthropic's findings.
A Chinese-speaking group tracked as GTG-10007, likely based in Changsha, deployed what Anthropic calls "agent swarms" for reconnaissance and post-exploitation work. Remarkably, two of the group's operators were identified as undergraduate students. Their automated exploit foundries targeted approximately 50 organizations and produced "more than a dozen possible zero-day findings" in a single month, demonstrating how AI has democratized access to sophisticated attack capabilities.
Steps Organizations Can Take to Defend Against AI-Enabled Threats
- Implement Identity Verification: Anthropic now requires accounts operating from unsupported countries such as China, Russia, and Iran to verify their identity or lose access to Claude, a measure organizations should mirror by enforcing multi-factor authentication and geographic access controls.
- Monitor for Reasoning Transcript Extraction: Anthropic modified Claude to summarize its internal reasoning before responding, making stolen transcripts less useful for training competing models. Organizations should audit logs for unusual patterns of reasoning-heavy queries that could indicate distillation attempts.
- Coordinate Threat Intelligence Sharing: Anthropic emphasized that "no company can solve this alone" and called for coordinated responses across the AI industry, cloud providers, and policymakers. Organizations should participate in industry threat-sharing initiatives and report suspicious activity to relevant authorities.
- Strengthen Safeguards on Dual-Use Research Queries: Anthropic deployed stronger safeguards restricting access to a wide range of dual-use biological research queries in its newer models. Organizations using frontier AI should implement similar content filters for sensitive research domains.
Anthropic attributed one of the state-sponsored campaigns to GTG-20006, which the company said is consistent with public reporting on the Russian espionage group Midnight Blizzard. Ukrainian government, military, and diplomatic staff were the group's most frequent targets. The attackers bulk-exported mailboxes from at least two drone component makers, stole proprietary software development kits for drone vision systems, and compromised hotel guest Wi-Fi vendors to reach travelers.
The report also documented a Russian-speaking financially motivated actor, GTG-50020, that shifted its focus to targeting AI companies after earlier intrusions against hotel booking and financial technology platforms. The group planted malicious instructions in an AI vendor's automated evaluation sandbox to extract production API keys for several model providers, then launched a follow-on campaign targeting roughly 30 AI companies in about four days.
What Is the Scale of Model Distillation Attacks Against Claude?
Beyond direct misuse, Anthropic documented an industrial-scale campaign to extract Claude's capabilities and replicate them in competing models without authorization. The company accused seven Chinese AI labs of conducting what it calls "distillation" attacks, in which attackers force AI models to reveal their internal reasoning and use those transcripts to train rival systems.
Anthropic identified Alibaba Group, Moonshot AI, and DeepSeek as conducting the largest distillation campaigns. Alibaba's operation forced Claude Opus 4.6 and 4.7 to write out their chain-of-thought reasoning, and the transcripts were used to train Qwen 3.5, 3.6, and 3.7. The campaign peaked at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts, with more than 151 million total exchanges recorded between May and July.
Moonshot AI and DeepSeek quietly forwarded their own customers' requests to Claude and saved the answers for training purposes. In one 10-day stretch, Moonshot relayed almost 300,000 requests from users who believed they were interacting with Kimi, Moonshot's own AI assistant. Sensitive data accompanied these requests, including surveillance camera footage from hundreds of cameras in Chengdu uploaded by a user Anthropic assessed as likely affiliated with China's People's Liberation Army.
The other labs accused of distillation include Xiaomi, Zhipu, SenseTime, and MiniMax. Anthropic noted that MiniMax established a proxy service through an undisclosed shell company that sells access exclusively to Anthropic and OpenAI models, effectively creating a backdoor for extracting model capabilities.
"Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity," Anthropic stated in its report.
Anthropic, Threat Intelligence Team
Anthropic's disclosure comes amid broader industry concerns about frontier AI safety. The company emphasized that as models become increasingly capable, their risks increase unless AI developers and society's defenders act to make them safer. The report represents Anthropic's third threat disclosure since March 2025, reflecting an ongoing commitment to transparency about misuse of its systems.
The company concluded its threat report with a call to action across the industry, stating that attacks at this scale require a coordinated response across the AI industry, cloud providers, and policymakers. By publishing detailed evidence of these threats, Anthropic aims to make the information available to everyone with a stake in the outcome, from security researchers to government regulators.