Anthropic says it has disrupted operations using Claude for espionage, surveillance, weapons development, and fraud, with some attackers using AI to perform work that previously required teams of specialists.
Its 154-page report, published on September 10, covers activity disrupted between December 2025 and August 2026 across seven harm areas. The company describes the cases as notable examples, rather than a representative picture of misuse. They include confirmed data theft, experimental weapons software, and research with potentially dangerous applications.
Suspected affiliates of the ShinyHunters cybercrime collective stole more than a terabyte of data from a technology provider, including millions of payment-card records, according to Anthropic. They placed stolen material on a public website to pressure the victim into paying. In another intrusion, attackers progressed from a stolen developer credential to full administrative control of a victim’s cloud environment in roughly three hours.
An operation consistent with Russian state-linked espionage used AI to automate phishing and revise malware when security products detected it. Across the cyber cases, Anthropic identified a shift towards attacks spanning multiple victims with fewer operators. Humans nevertheless retained key decisions, including target selection and how to profit from stolen information.
In Bangladesh, a single operator in Gaibandha rotated through 29 Claude accounts to generate at least 1,500 fabricated headlines and 300 false narratives. The material promoted the Awami League and attacked its opponents. Anthropic found no proof that the party directed or funded the operation, and no evidence that its content reached beyond the identified social media accounts.
The report details nine influence operations, including fake news outlets, fabricated political personas, and state-aligned propaganda production. Most content attracted little or no genuine engagement. The widest authentic reach came through established broadcast channels, illustrating the distinction between producing large quantities of propaganda and successfully distributing it.
In Mali, a single subscriber, assessed to be a consultant working with the state intelligence service, used Claude to help engineer “Lakana 360”. The surveillance platform targeted roughly 25 million SIM cards across the country’s three national mobile operators.
According to the report, the operator removed a warrant requirement from the component generating intelligence dossiers on phone numbers. Anthropic banned the account, but the platform ran locally using other models, so the ban did not disable the deployed system.
Other investigations identified China-based operations profiling religious leaders, dissidents, and overseas activists. Iranian security-linked units used Claude to develop surveillance tools, including a Firefox extension disguised as a prayer-times utility that collected social media identities.
A group in northern Yemen used Claude to develop guidance software for weapons programmes and conducted a guided-rocket test. The test appeared to fail, and the operators returned to Claude within hours to investigate. Anthropic found no evidence that they successfully fielded an operational device.
A Russia-based team used Claude to develop software for an autonomous attack-drone swarm designed to select targets, including people, and issue detonation commands without human intervention. The report documents simulation and testing involving real hardware, rather than confirmed battlefield deployment. Anthropic assessed the operators to be a specialised freelance team, not a Russian state entity.
Five cases involved scientific work that Anthropic assessed could support biological weapons development, including research involving viruses and toxins. The users were working scientists. “We do not assert that they intended harm,” the company said, withholding their identities and institutions to avoid exposing them to danger.
The central difficulty was dual use: research relevant to weapons can also support vaccines and medicines. In one avian-influenza case, safeguards restricted the researcher to weaker models, limiting the assistance provided. Other research passed through safety filters because its potentially beneficial and harmful applications were difficult to separate.
Anthropic did not present the cases as evidence of an imminent biological threat enabled by Claude. Instead, it argued that increasingly capable scientific models would require checks on users and institutions alongside content filters.
A China-based app studio used Claude to build more than 20 dating apps and operate over 4,700 AI personas, despite advertising the services as entirely human. Those personas communicated with at least 25,000 people during a two-week period in April.
Users bought in-app coins to replenish messaging and matching allowances. The network mixed bots with paid human workers, who provided live video calls and social media interactions to make the services appear genuine. Anthropic said it banned associated accounts and shared findings with other AI providers and app-store operators.
Anthropic also reported unauthorised “distillation” campaigns attributed to seven China-based AI labs. Distillation is a legitimate training technique, but the company alleged that these operations used deceptive access networks to extract Claude’s capabilities without permission.
Its concern extended beyond commercial copying. Anthropic said capabilities could transfer to other models without the safeguards controlling their use. It also identified sensitive customer conversations, company information, and credentials being passed between services, raising privacy concerns.
Anthropic said it strengthened safeguards and shared intelligence with authorities and industry partners where appropriate. But the report also records failures: some users obtained harmful assistance, others returned under fresh identities, and software built with Claude could continue running elsewhere.
In one biology-related case, an intermediary regained access within days of being banned. The findings therefore document disrupted access and strengthened defences, not a guarantee that every underlying operation stopped.