Logo
FrontierNews.ai

Claude AI Used for Bioweapons, Missiles, and Espionage: What Anthropic's Threat Report Reveals

Anthropic has disclosed that its Claude AI models were misused in dozens of serious cases involving biological weapons research, missile and drone development, mass surveillance, cyber espionage, and data theft between December 2025 and August 2026. The company identified and disrupted activity involving suspected state-backed groups, criminal networks, propaganda organizations, and politically motivated actors. These represent some of the most severe misuse incidents the company has detected to date.

What Types of Misuse Did Anthropic Detect?

Anthropic's threat report, released in September 2026, documented a wide range of malicious activities across seven harm categories. The incidents involved Claude Haiku, Sonnet, and Opus models, though the company noted that its most advanced models, Fable and Mythos, were not involved except in one distillation case.

The company identified five biological misuse cases, some involving scientists whose work could have legitimate research purposes but carried significant risks. In one case, a scientist sought help with a grant proposal for gain-of-function research on chikungunya virus, proposing mutations intended to make the virus more harmful through repeated infections in live animals. Anthropic said it believed the work was linked to a military research institute. Although Claude's biological safety system blocked the request, the user reportedly bypassed the restriction through a third-party evasion service.

On the weapons development front, Anthropic disrupted six cases involving attempts to use Claude for conventional weapons development. These included three incidents in China, two in Russia, and one in Yemen. In Yemen, a group reportedly used Claude Code for engineering work connected to a guided rocket and a multistage ballistic missile designed to travel more than 2,000 kilometers. In Russia, an operator allegedly used Claude Code to develop an autonomous FPV kamikaze drone swarm capable of selecting targets and detonating without human intervention. In China, an account potentially linked to the military-industrial sector used Claude to build a 16-module electronic warfare and air-defense suppression system that later moved from simulations to 12 real targets in Taiwan.

How Is AI Changing Cyberattacks and Surveillance?

One of the most significant findings in Anthropic's report is how attackers are using AI to automate entire attack sequences rather than simply asking for code or technical advice. Instead of a human using AI output to conduct an attack, multi-agent systems now perform tasks like reconnaissance, exploitation, and data theft with minimal human involvement.

Anthropic identified nine surveillance-related cases involving multiple countries and targets. One China-linked operation allegedly used Claude to track, profile, and recruit Uyghurs and journalists connected to the Syrian Army, processing WhatsApp and Telegram data while using Claude for profiling, translation, and role-playing aimed at testing deception. The company also reported surveillance activity targeting Catholic cardinals, the Presbyterian Church in Taiwan, Tibetan Buddhists, and Falun Gong members. In Iran, two linked units using 16 Claude accounts reportedly profiled 6,388 Iranians over a year and analyzed 155,216 tweets to identify 39 opposition accounts.

A Russian-speaking actor used Claude in attacks on more than 20 Ukrainian and European government, defense, and diplomatic organizations, along with drone manufacturers. The actor allegedly stole a drone vision-system software development kit, manipulated hotel Wi-Fi DNS records to distribute malware, accessed officials' WhatsApp accounts, and obtained more than 300,000 national identity records and 500,000 company registry records from a North African government body.

Why Does AI Lower the Barrier for Sophisticated Attacks?

A critical insight from Anthropic's research is that AI is reducing the skills and resources traditionally needed to execute sophisticated cyberattacks. The company observed that state-sponsored groups, financially motivated criminals, and individual operators can now execute campaigns that would previously require teams of highly skilled specialists. AI can assist with reconnaissance, tool development, data processing, and exfiltration, making it possible for someone with relatively limited technical expertise to carry out operations that once demanded significant expertise.

The report highlighted a threat actor Anthropic calls GTG-20006, whose assessment is consistent with public reporting linking the group with Russian-linked Midnight Blizzard. This group targeted military intelligence organizations, government agencies, diplomatic organizations, and defense-related firms in Ukraine, Europe, and select targets elsewhere. AI was used across much of the operation, including reconnaissance, phishing infrastructure building, access maintenance, data extraction, and malware modification. Particularly concerning was the use of AI agents to monitor whether malware had been detected by security products and automatically modify and rebuild the malware to evade defenses.

How to Strengthen Defenses Against AI-Enabled Threats

  • Deploy AI-Powered Detection Systems: Organizations should implement AI-driven security tools to identify suspicious activity and detect threats before they can be exploited, rather than relying solely on traditional reactive defenses.
  • Automate Vulnerability Discovery: Security teams need to use AI themselves to find vulnerabilities in their systems and strengthen them proactively, staying ahead of attackers who are increasingly automating the attack chain.
  • Implement Identity Verification and Account Monitoring: Anthropic responded to misuse by requiring identity verification for accounts showing signs of abuse and improving detection systems to identify proxy networks and fraudulent account patterns.

Anthropic also disrupted at least nine influence operations involving Russia, China, Iran, Bangladesh, and Kenya. One case involved Russian state-media insiders using Claude to prepare content for Sputnik Moldova, while another used Claude for pro-Russia and anti-France content for Radio Lengo Songo in Bangui, along with forged documents.

Financially motivated groups also exploited Claude. In one case linked to ShinyHunters affiliates, operators downloaded 1.8 million Android app packages and searched them for hardcoded secrets. Related incidents involved more than 1 terabyte of stolen data, tens of millions of airline passenger records, and a software supply-chain breach. In China, Anthropic found more than 20 dating apps marketed as "fully human" but powered largely by Claude personas. Over two weeks, more than 4,700 AI personas reportedly sent 2.36 million messages to at least 25,000 real users.

Perhaps most troubling, Anthropic accused networks linked to Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax of illicitly extracting Claude's outputs to train competing models. The Alibaba-linked campaign reportedly generated nearly 3 million exchanges per day at its peak, with more than 151 million exchanges between May and July 2026 through over 3,500 fraudulent accounts. Moonshot AI allegedly forwarded around 300,000 requests to Claude over 10 days, while DeepSeek was linked to 12.1 million exchanges in 14 days.

Anthropic responded to these misuse cases by banning accounts, improving detection systems, tracing proxy networks, and requiring identity verification for accounts showing signs of abuse. The company warned that such misuse could increase as AI models become more capable and said sharing these cases could help other AI developers strengthen their own safety measures.