Anthropic's Threat Report Reveals How Claude Is Being Used for Surveillance, Weapons, and Hacking
Anthropic has published a detailed threat intelligence report documenting how its Claude AI models were misused for cyberattacks, government surveillance systems, weapons development, and biological research between December 2025 and August 2026. The company detected and shut down these operations, banning accounts and strengthening safeguards while sharing intelligence with authorities and industry partners.
What Types of Harm Did Anthropic Detect?
Anthropic's Threat Intelligence team identified misuse across seven distinct harm categories. The company involved its Claude Haiku, Sonnet, and Opus models in these cases, with one exception involving distillation of its Fable or Mythos-class models.
- Cyber Operations: AI narrowed the gap between well-resourced state hackers and lone operators, with breaches completed in two to three hours and dozens of victims handled in parallel by single operators
- Surveillance Systems: State-aligned actors and commercial spyware vendors used Claude to build surveillance platforms across China, Iran, and West Africa, monitoring millions of people
- Conventional Weapons Development: Six documented cases involved using Claude Code to develop guidance and control software for guided rockets, ballistic missiles, and hypersonic glide vehicles
- Biological Research: Five cases involved requests that could support biological weapons development, including gain-of-function research on dangerous pathogens
- Influence Operations: Coordinated campaigns designed to manipulate public opinion, though most drew little authentic engagement before disruption
- Scams and Fraud: Financially motivated misuse targeting individuals and organizations
- Illicit Distillation: Covert extraction of Claude's capabilities to train rival AI models
How Are State Actors Using Claude for Surveillance?
The surveillance cases represent perhaps the most striking misuse pattern. Anthropic documented state-aligned actors deploying Claude-powered systems to monitor populations at scale. One case involved a Bamako-based consultant working with Mali's state intelligence service who used Claude as an engineering workforce to build a platform called Lakana 360. This system monitored approximately 25 million SIM cards across all three of Mali's mobile operators and bypassed legal requirements for court orders before operators could disclose certain records.
In China, Anthropic identified a religious affairs intelligence unit that had dramatically reduced its workforce while increasing output. The unit now produces thousands of investigations monthly using an AI assistant. Another Chinese case involved Claude scoring social media posts by political sensitivity and flagging people for what operators termed "control." Iranian actors deployed a malicious Firefox extension powered by Claude that harvested users' identities from social networks.
"They're effectively automating parts of the job within the intel apparatus. Authoritarian states are using AI for surveillance, repression and influence operations today," said Jacob Klein, who leads threat intelligence at Anthropic.
Jacob Klein, Head of Threat Intelligence, Anthropic
Klein emphasized that AI was making state surveillance cheaper and more efficient, though it was not changing who governments target. The pattern is no longer theoretical; it is happening today across multiple authoritarian regimes.
What Role Did Claude Play in Cyberattacks?
The largest section of Anthropic's report covers cyber operations, documenting how AI has democratized sophisticated hacking. One case tracked as GTG-20006 involved a Russian-speaking operator running espionage against Ukrainian and European government targets, including diplomatic and defense organizations. The actor used Claude to check whether security products had flagged their malware, then automatically rebuilt it to slip past detection. Anthropic attributed this operation to the group known as Midnight Blizzard based on public reporting.
In another case, two undergraduate students in Hunan, China ran what Anthropic called "agent swarms" against roughly fifty organizations. These included a Southeast Asian government agency from which the actors retrieved citizen records. The ability to conduct these multi-victim campaigns with minimal human resources represents a fundamental shift in the threat landscape.
How Is Claude Being Used for Weapons Development?
Anthropic documented six cases of Claude being used to develop software for conventional weapons. Three cases originated in China, two in Russia, and one in Yemen. In the Yemen case, a cell in the north of the country ran three weapons programs using Claude Code in place of software engineers. These programs included a guided rocket, a multi-stage ballistic missile with a stated range goal exceeding 2,000 kilometers, and missile variants including a hypersonic glide vehicle. The actors test-fired a guided rocket, though the test appears to have failed.
Russian cases involved freelance actors working on autonomous kamikaze drone swarms. Anthropic stressed that these findings represent a new form of misuse where AI models are substituting for specialized engineering expertise in weapons development.
What About Biological Weapons Concerns?
Anthropic identified five cases where its models were used in ways that could support biological weapons development. The company acknowledged that making these judgments is extremely difficult and withheld the names of institutions, countries, and specific biological agents involved. The individuals in question were working scientists, and Anthropic did not assert that they intended harm.
One example from May involved a request for help writing a grant application for gain-of-function research on the chikungunya virus. The work was intended to be carried out at a military research institute. Anthropic noted that older models such as Claude Opus 4 were well below the level where they could meaningfully assist such work, but the company has launched more recent models with stronger safeguards.
"You are not seeing someone in a comic book kind of way say, 'Hey, I want to build a biological weapon to kill everybody.' It's an incredibly nuanced situation," said Jacob Klein.
Jacob Klein, Head of Threat Intelligence, Anthropic
How Are Chinese Companies Distilling Claude's Capabilities?
Anthropic identified a coordinated distillation campaign where seven China-based labs covertly extracted Claude's capabilities to train rival models. The company defines illicit distillation as silently forwarding customer requests to Claude and displaying the responses as though they came from the rival's own model. Moonshot AI, which operates the Kimi model, relayed almost 300,000 requests through a network of 5,380 fraudulent accounts over a single ten-day period. Anthropic attributed more than 23 million exchanges to Moonshot between May and July.
The company made similar allegations against DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax. Some of the relayed queries exposed sensitive user data, including live credentials tied to a Russian defense agency. These findings align with earlier U.S. intelligence advisories naming six Chinese firms, though Beijing has rejected those claims.
How to Understand Anthropic's Response to These Threats
- Account Bans: Anthropic banned all accounts involved in detected misuse and worked to prevent future access by the same actors
- Safeguard Strengthening: The company enhanced its safety measures across Claude models to prevent similar misuse patterns in the future
- Intelligence Sharing: Anthropic shared threat intelligence with government authorities and industry partners where appropriate, contributing to broader ecosystem security
- Transparency Reporting: The company published detailed findings to give governments and civil society a clearer view of how AI threats take shape in the real world
Anthropic said it published the report out of an obligation to disclose misuse and to help stakeholders understand the evolving threat landscape. The company emphasized that while AI is enabling new forms of harm, the underlying intent and targets of malicious actors remain consistent with historical patterns. What has changed is the efficiency and scale at which individuals and small teams can now operate.