Anthropic reveals Claude misuse in espionage, surveillance and bioweapons
In Short
Anthropic has revealed several instances where it detected countries and groups attempting to misuse Claude. According to the company, these cases included attempts to create biological weapons and mass surveillance systems, as well as incidents of espionage.

Anthropic reveals Claude misuse in espionage, surveillance and bioweapons
AI tools are quite advanced today. However, as companies like Anthropic and OpenAI develop more sophisticated AI models, the risk of potential misuse has only increased. In a detailed safety report, Anthropic has revealed how countries and groups are attempting to misuse Claude, including incidents involving espionage, mass surveillance, and biological weapons.
In the report, Anthropic details a series of attempts it managed to thwart between December 2025 and August 2026. According to the company, the cases involved alleged state-backed groups, profit-motivated criminals, propaganda networks, spyware providers, and politically motivated actors.
The Claude Haiku, Sonnet, and Opus models were the ones used in the cases described by the company. Anthropic noted that none of the misuse cases involved models from the Claude Fable or Mythos classes, with the exception of a single instance of model distillation. It stated that these examples did not represent typical misuse, but rather the most notable and novel threat activity they had identified to date.
Using Claude for biological weapons?
Anthropic explained that the most sensitive cases involved biological research conducted by practicing scientists—including some described as state-backed users—since it was not always possible to determine whether their work was legitimate or intended for malicious purposes.
Anthropic stated that it chose to err on the side of caution, arguing that legitimate biological research can overlap with work that would facilitate the creation of dangerous pathogens. "We aren't dealing with someone who, comic-book style, says, 'Hey, I want to build a bioweapon to kill everyone,'" said Jacob Klein, Anthropic’s head of threat intelligence, in an interview. "It is an incredibly complex and nuanced situation."
Anthropic documented five case studies regarding the misuse of technology in the biological realm. In one instance from May, a scientist sought assistance in drafting a grant proposal for gain-of-function research on the chikungunya virus—a mosquito-borne disease that can cause severe pain and other symptoms for months. The company explained that the proposed research involved engineering mutations to make the virus more harmful as it repeatedly infected live animals. Anthropic noted that the request was concerning, partly because the work appeared intended for a military research institute.
According to Anthropic, the instance was blocked by its biosecurity classifier, but the user managed to bypass the safeguard using a third-party evasion platform that automatically switched to a competitor's model when Claude refused the request.
In another instance, Anthropic revealed that an intermediary service (relay) used by various clients allowed a user to draft—from start to finish and in about an hour—a funding proposal to research how orthopoxviruses evade the immune system. Orthopoxviruses are a family of viruses that cause diseases in humans, including smallpox. In a separate case, a researcher planning experiments to adapt avian influenza to mammals over several weeks was restricted throughout the process to using Anthropic’s less powerful models.
Anthropic also halted two state-sponsored programs aimed at redesigning poisons or toxins and, following an exhaustive 30-day analysis of state-linked activities, identified approximately 35 distinct research projects; while most involved legitimate civilian science, some carried potential dual-use risks. "We do not claim there was intent to cause harm, and revealing their identities or those of their laboratories could expose them to risk," the company noted.
Anthropic reported that users had bypassed controls designed to prevent access from countries where Claude is unavailable and had attempted to conceal the purpose of their research. The company blocked the accounts; in biology-related cases, it went beyond mere suspension to implement outright refusals, restrict access to lower-capability models, and conduct proactive reviews.
State-linked groups attempting to build weapons using AI
In addition to biological weapons, Anthropic claims to have detected attempts to use Claude to develop software for conventional weapons, such as firearms, missiles, armed drones, and bombs. According to the company, three such cases were identified in China, two in Russia, and one in Yemen. Regarding Yemen, the company reported that a group of malicious actors used Claude Code—instead of human engineers specializing in guidance, navigation, and control—to develop software for a guided rocket, a multi-stage ballistic missile with a projected range exceeding 2,000 kilometres, and a hypersonic glide vehicle variant. Anthropic noted that the group conducted a test launch of the guided rocket and that the test appeared to fail.
In Russia, Anthropic detected an independent operator linked to an initiative known as DronDoc or Serafim who was using Claude Code to develop a swarm of autonomous kamikaze drones featuring a first-person view (FPV) system and a full-stack architecture. The company stated that the integrated model could select targets—including the "person" category—and detonate without human intervention, relying on visual training based on combat footage from Ukraine obtained through scraping techniques.
As for China, Anthropic noted that an account—described as possibly linked to the military-industrial sector—used Claude to develop a 16-module electronic warfare and air defence suppression system. According to the company, the user subsequently shifted from a simulation in a generic scenario to one focused on 12 real targets in Taiwan, including a command bunker and Patriot and Tien Kung missile batteries.
Anthropic claims China and Iran attempted to use Claude for surveillance tasks
Weapons are not the only target for those seeking to misuse AI tools like Claude. Apparently, many groups wish to use AI to conduct mass surveillance operations. Anthropic recorded nine such cases. In one instance, a group with alleged ties to China used Claude to track, profile, and recruit members of the Uyghur population and journalists connected to the Syrian military. The company noted that the operation utilised massive amounts of data from monitored WhatsApp and Telegram chats to create profiles, and that Claude was also used for real-time translation and role-playing simulations designed to test deception tactics.
Anthropic also described surveillance activities originating in China that targeted Catholic cardinals, the Presbyterian Church of Taiwan, Tibetan Buddhists, and Falun Gong practitioners. It reported that one actor rephrased a query after an initial refusal and obtained guidelines for suppressing information regarding 10 private citizens, as well as pre-operation intelligence on protests abroad.
Regarding Iran, Anthropic reported that two linked units, using 16 Claude accounts, claimed to have monitored or profiled 6,388 Iranian citizens over the course of a year, analysed 155,216 tweets to identify 39 opposition accounts, and used a malicious Firefox extension to gather identities and feed them into a shared case management system called Arman. The company noted that an Iran-linked actor also used Claude to identify U.S. naval targets. Anthropic stated that its usage policy prohibits surveillance and profiling without consent.
Use of Claude for espionage
In the realm of cyber operations, Anthropic noted that AI has enabled groups to automate the reconnaissance, exploitation, and monitoring phases. A Russian-speaking actor used Claude in attacks against more than 20 government, defence, and diplomatic targets in Ukraine and Europe, as well as against drone manufacturers. According to Anthropic, the individual stole a complete software development kit for drone vision systems and hijacked Domain Name System (DNS) records for hotel Wi-Fi networks to install malware on guests' devices. Subsequently, the actor took control of officials' WhatsApp accounts by disabling read receipts and obtained over 300,000 national identity records and more than 500,000 commercial registry entries from a North African government agency.
The company noted that AI-based monitoring agents detected when security products flagged the malware and autonomously rewrote it to evade detection once again. Anthropic reported that it blocked the accounts, developed new detection systems based on behavioural patterns, and collaborated with Microsoft, whose own reports on the hotel Wi-Fi technique corroborated the findings.
Another group linked to China—including two university students—was found to be using parallel AI workflows to reverse-engineer firmware, gather open-source intelligence on foreign governments, and conduct scheduled intelligence-gathering operations, affecting approximately 50 organizations worldwide.
Regarding influence operations, Anthropic detected groups using Claude both to plan campaigns and to generate the false or misleading content itself. The company claims to have disrupted at least nine such initiatives—linked to Russia, China, Iran, Bangladesh, and Kenya—and notes that the greatest real-world reach occurred when state media, including radio and television, served as the dissemination channel.
Notable cases included individuals linked to Russian state media—such as a former editor-in-chief of Sputnik Moldova—who used Claude as an assistant editor to generate content for that outlet. Anthropic also reported that a Russian-speaking coordinator in Bangui employed Claude for Radio Lengo Songo—a station founded by the Wagner Group—to create pro-Russian and anti-French content, forge Central African Republic government documents, and draft human resources paperwork. The company noted that Claude refused a request to identify real individuals as militants targeted for security operations.
Security breaches and a fake dating site
Another instance of misuse involved financially motivated groups. In a case linked to ShinyHunters affiliates, the company discovered that operators downloaded 1.8 million Android application packages and analysed them for hardcoded credentials or access keys, fueling a credit card fraud operation (carding) managed via Telegram. Related breaches included the theft of over 1 TB of data from a technology provider, records of tens of millions of airline passengers, and a software supply chain compromise.
Anthropic reported detecting a China-based network in April 2026 comprising over 20 dating apps that marketed themselves as "fully human" but largely operated using personas generated by Claude. Over a two-week period, the company identified more than 4,700—or nearly 5,000, depending on the counting method used in the report—AI personas, which sent 2.36 million messages to at least 25,000 real users. Anthropic stated that the network combined AI personas with gig workers at a ratio of approximately three to one and instructed the personas never to reveal their automated nature. The company stated that it had blocked the accounts and organisations involved.
Competitors engaging in Claude distillation
So far, we have analysed cases linked to countries or malicious actors, but Anthropic has also documented incidents where rival AI companies used Claude. The company stated that competing firms and associated networks had attempted to use outputs generated by Claude to train their own models—a practice it termed "illicit distillation."
The campaigns mentioned include those linked to Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax. Anthropic noted that the largest campaign detected—attributed to Alibaba—peaked at nearly three million daily interactions and exceeded 151 million exchanges between May and July 2026, utilizing more than 3,500 fraudulent accounts.
Moonshot AI, the company behind the Kimi K3 AI model, discreetly redirected approximately 300,000 user requests to Claude over a 10-day period, while DeepSeek employed a similar relay technique to generate 12.1 million interactions in 14 days.
Anthropic responded by blocking accounts, tracing proxy networks hidden behind resellers, strengthening extraction classifiers, summarizing internal reasoning within responses, introducing a "preserved thought" feature, and requiring identity verification for accounts showing signs of misuse.
The company reported that, across the seven identified risk categories, it proceeded to remove accounts, bolster security measures, and—where appropriate—share information with authorities, researchers, industry partners, and victims. Furthermore, Anthropic explained that it was publishing this report because misuse tends to increase as models gain greater capabilities, unless developers and defenders take action to make them safer; Furthermore, it hopes that these findings will help other platforms identify similar patterns and improve collective defences.
Rajasthan: As rain returns, yellow alert issued for Alwar, Dholpur
Mayawati attacks SP, Cong over use of blue colour; says symbolism can't erase casteist mindset
‘Bigg Boss 20’: Yung DSA tells Aamrapali Dubey he’s controlling his temper in the house
Stronger engagement among BRICS economies can unlock new opportunities: Assocham
Stronger engagement among BRICS economies can unlock new opportunities: Assocham
Maneka Gandhi advocates against depiction of animal cruelty in films, says viewers get influenced by movies
PM Modi Confident Of Positive Talks At BRICS Summit, Says Global Welfare Is The Goal
US marks 25 years since the September 11 attacks, 'moments that divide time'
Statistical heights, market depths: Shiv Sena(UBT) in 'Saamana' on Centre's economic vision
Heavy Rain Predicted in AP and Telangana for three days

