Yesterday, Anthropic released a 154-page threat intelligence report detailing how criminals, spies, and propagandists tried to weaponize Claude between December 2025 and August 2026.
It covers seven categories: cyberattacks, propaganda, surveillance, weapons development, biological research, scams, and a newer problem called illicit distillation, where rival labs secretly copy Claude’s abilities into their own models.
Cyberattacks
AI has erased the gap between a lone hacker and a state intelligence agency.
A Russian-speaking group linked to the espionage outfit known as Midnight Blizzard used Claude to run phishing operations and automatically rewrite malware whenever antivirus software caught it, breaking into Ukrainian and European government targets with almost no human involvement.
They also hijacked hotel WiFi to intercept guests’ traffic and stole 300,000 national ID records from a North African government.
A crew linked to the ShinyHunters extortion group scanned 1.8 million Android apps for leaked passwords, then breached companies for ransom, in one case going from first access to full data theft in a few hours.
Separately, Chinese-speaking operators, some reportedly college students, built an automated “exploit foundry” that had Claude hunt for unknown software vulnerabilities around the clock, producing over a dozen potential zero-days in a month.
Criminals also targeted the AI industry itself: one Russian actor stole a company’s API keys and attacked thirty AI companies in four days trying to reach an unreleased Claude model (they failed), while another ran fake “cheap Claude access” sites that stole users’ real login credentials.
Propaganda
Nine influence campaigns from Russia, Iran, Turkey, and elsewhere targeted audiences on six continents, several timed to real elections.
A Russian-aligned operator in the Central African Republic used Claude to write pro-Russia radio content for a station reportedly founded by the Wagner Group, and even to grade journalists’ loyalty and fire underperformers.
A French ad agency built 70 fake local news sites in 20 languages, switching political sides depending on who was paying.
In Malaysia, a platform marketed as a “military-grade political operations ecosystem” used real voter data to target citizens by race and religion and requested a million fake views for the prime minister, though Claude refused to help draft outright defamation.
Russian state media used Claude to turn Moldovan news into propaganda broadcast on Sputnik and RT.
Surveillance
An Israeli-Singaporean firm used Claude to profile social media users in Iran and the Gulf by political leaning.
Separately, three China-aligned groups used Claude for what they described as “stability maintenance.” One tried to recruit Uyghurs serving in Syrian armed groups by targeting people whose families were still in Xinjiang.
Another created daily intelligence profiles on Catholic cardinals, Tibetan Buddhist advocates, and Falun Gong practitioners, including immigration records and building floor plans.
Claude refused more serious requests, including help with covert interrogations.
Weapons
A cell in Yemen used Claude Code to write guidance software for a rocket, a long-range missile, and a hypersonic glide vehicle, dividing the work across multiple Claude instances like a small engineering team. They test-fired a rocket; it failed, and they returned to Claude within hours to debug it.
A Russian freelance team built an autonomous drone swarm capable of picking human targets without approval, trained on scraped Ukrainian combat footage.
Chinese actors used Claude to draft naval weapons acquisition documents, build electronic warfare software simulating strikes on Taiwan, and research American directed-energy weapons.
Biology
This section shows how hard it is to draw the line, since most useful biology research is dual-use.
Anthropic blocked a gain-of-function (medical research that genetically alters an organism to enhance its biological functions) chikungunya research grant tied to a military institute, but the operators rerouted the work to a less-restricted competitor model.
Weaker, older Claude models were used for weeks by a researcher studying mammalian adaptation of bird flu, an outcome Anthropic attributes to its safety systems automatically limiting access.
A single account drafted a complete smallpox-family virus grant in about an hour, and other researchers redesigned toxins while explicitly asking Claude to keep descriptions vague in progress reports.
Scams
A Chinese studio ran over 20 dating apps secretly powered by roughly 4,700 AI personas chatting with at least 25,000 real users, mixed with paid human workers for video calls, and engineered to behave innocently during app store review before switching on deceptive features.
Distillation
Rival Chinese labs were caught secretly harvesting Claude’s reasoning to train their own models.
Alibaba ran the largest attack Anthropic has measured, over 151 million exchanges in three months, to train Qwen.
Moonshot and DeepSeek secretly routed their own users’ requests to Claude without telling them, exposing sensitive data including Russian defense credentials, then served Claude’s answers under their own brand. Zhipu and Xiaomi ran similar operations at smaller scale.
Anthropic says it banned every account involved, tightened its safeguards accordingly, and shared findings with law enforcement and other AI labs, while acknowledging the misuse keeps evolving as fast as the defenses.


























