Anthropic Exposes AI Misuse: Bioweapons, Espionage And Surveillance Linked To Claude

2

Anthropic Reveals How Claude Was Misused For Bioweapons, Surveillance And Espionage

The growing capabilities of artificial intelligence are also creating new opportunities for misuse. Anthropic, the company behind Claude, has detailed a series of cases in which its AI models were allegedly used for biological research, weapons development, mass surveillance, cyberattacks, espionage and influence operations.

In a new safety report, Anthropic examined misuse attempts detected or disrupted between December 2025 and August 2026. The company said the cases involved suspected state-backed groups, cybercriminals, propaganda networks, spyware operators and politically motivated actors.

The activity involved Claude Haiku, Sonnet and Opus. Anthropic said the cases highlighted in the report were among the most significant and unusual threats it had identified, rather than examples of routine AI misuse.

Claude And Sensitive Biological Research

Some of the most concerning cases involved biological research. Anthropic said several users were working on projects that could have legitimate scientific applications but also carried potential risks because similar research could be used to develop harmful pathogens.

The company documented five biological misuse cases. In one incident, a scientist sought assistance with a grant proposal involving gain-of-function research on chikungunya virus. Anthropic said the proposed research involved modifying the virus through experiments on live animals and that it believed the work was connected to a military research institute.

The request was blocked by Anthropic’s biological safety system. However, the company said the user later attempted to bypass the restriction using a third-party service.

Another case involved a user who was reportedly able to prepare an orthopoxvirus immune-evasion grant application through a reseller relay. Anthropic also described a researcher conducting planned experiments involving the adaptation of avian influenza to mammals who was restricted to a lower-capability model.

The company said it disrupted two state-backed programmes involving venom or toxin redesign. A separate 30-day review of state-linked activity identified about 35 research efforts, although Anthropic said most appeared to involve legitimate civilian science.

According to the company, some users had circumvented geographical restrictions on Claude and attempted to disguise the purpose of their research. Anthropic said it responded with account bans, refusals, access restrictions and proactive monitoring.

AI Used In Weapons Development

Anthropic also identified attempts to use Claude for the development of software associated with conventional weapons.

The company reported three cases in China, two in Russia and one in Yemen involving technologies such as missiles, armed drones and other weapons systems.

In Yemen, Anthropic said a group used Claude Code for work associated with a guided rocket, a long-range ballistic missile and a hypersonic glide vehicle variant. The company said the group conducted a test launch of the guided rocket, although the test appeared to fail.

In Russia, Anthropic identified an operator associated with an effort called DronDoc or Serafim. The company said Claude Code was used to develop software for an autonomous first-person-view drone swarm capable of identifying targets.

In China, Anthropic said an account potentially connected to the military-industrial sector used Claude to develop an electronic warfare and air-defence suppression system. The company said the activity later moved from generic simulations to scenarios involving real targets in Taiwan.

Surveillance Operations Targeted People And Organisations

Weapons development was not the only concern. Anthropic said it identified nine cases involving surveillance and profiling.

In one case, a group suspected of having links to China allegedly used Claude to track and profile Uyghur communities and journalists. The operation reportedly processed information from WhatsApp and Telegram communications and used Claude for translation and role-playing.

The company also described China-based surveillance activity targeting Catholic cardinals, the Presbyterian Church in Taiwan, Tibetan Buddhists and Falun Gong practitioners.

Anthropic said it identified similar activity in Iran. Two linked units reportedly used 16 Claude accounts to profile thousands of Iranians over a year. The operation allegedly analysed more than 155,000 tweets to identify opposition accounts and used a malicious browser extension to collect identities.

  • Anthropic also said an Iran-linked actor used Claude to identify US naval targets.
  • Claude Allegedly Used In Espionage Campaigns

The report also highlights cyber operations in which AI was allegedly used to automate reconnaissance, exploitation and monitoring.

Anthropic said one Russian-speaking actor used Claude during attacks targeting more than 20 Ukrainian and European government, defence and diplomatic organisations, as well as drone manufacturers.

The company said the actor obtained drone-related software, manipulated hotel Wi-Fi infrastructure to distribute malware and compromised officials’ WhatsApp accounts. The operation allegedly also obtained hundreds of thousands of identity and company records.

Anthropic said AI-based monitoring systems helped the attacker identify when malware had been detected and automatically modify it to evade security systems.

A separate China-linked group, which reportedly included two university students, allegedly used multiple AI workstreams for firmware analysis, open-source intelligence gathering and intelligence collection. Anthropic said around 50 organisations were compromised.

AI-Generated Influence Operations

Anthropic said it also disrupted at least nine influence operations linked to Russia, China, Iran, Bangladesh and Kenya.

The groups allegedly used Claude to plan campaigns as well as generate misleading content. The company said the campaigns achieved their widest reach when state-backed media organisations distributed the material through television and radio.

One case involved Russian state-media personnel who allegedly used Claude as an editorial assistant to produce content for Sputnik Moldova.

Another operation in Bangui reportedly used Claude to create pro-Russia and anti-France material for Radio Lengo Songo, a Wagner-founded station. Anthropic said the AI was also used to produce forged government documents and human-resources paperwork.

  • Criminal Groups Used Claude For Data Theft
  • Anthropic also found evidence of financially motivated misuse.

In one case linked to ShinyHunters affiliates, operators allegedly downloaded 1.8 million Android application packages and searched them for hardcoded secrets. The company said the information was connected to a Telegram-based carding operation.

The investigation also uncovered breaches involving more than 1TB of stolen data from a technology provider, tens of millions of airline passenger records and a software supply-chain compromise.

Fake Dating Profiles Powered By AI

Another case involved a China-based network of more than 20 dating applications marketed as being operated by real people.

Anthropic said the apps were largely powered by Claude-generated personas. During a two-week period, the company identified more than 4,700 AI personas, while another count in the report put the figure close to 5,000.

These personas allegedly sent around 2.36 million messages to at least 25,000 real users. Anthropic said the network combined AI personas with human gig workers and instructed the automated accounts not to disclose that they were AI-generated.

  • The company subsequently banned the accounts and organisations involved.
  • Rival AI Firms Accused Of Distilling Claude

Anthropic also reported what it described as “illicit distillation” — attempts by rival AI companies and related networks to use Claude’s outputs to train their own models.

The company named campaigns associated with Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax.

Anthropic said the largest campaign it measured was linked to Alibaba, reaching nearly three million exchanges per day at its peak and generating more than 151 million exchanges between May and July 2026 through more than 3,500 fraudulent accounts.

Moonshot AI allegedly forwarded about 300,000 customer requests to Claude over 10 days, while DeepSeek reportedly generated 12.1 million exchanges over a 14-day period using a similar approach.

Anthropic said it responded by banning accounts, tracing proxy networks, strengthening detection systems and introducing additional identity-verification measures for accounts showing signs of abuse.

Anthropic Warns Of More Sophisticated AI Misuse

Anthropic said it took action across all seven categories identified in its report, including removing accounts, strengthening safeguards and sharing intelligence with authorities, researchers, industry partners and affected organisations.

The company warned that misuse is likely to become more sophisticated as AI systems become more capable.

Anthropic said publishing details of the incidents could help other AI developers, governments and security teams recognise similar patterns and strengthen collective defences against emerging threats.

Comments are closed.