Bioweapons, surveillance, espionage: Anthropic reveals how Claude is being misused
AI tools are quite advanced today. But as companies like Anthropic and OpenAI continue to make more advanced AI models, the risk of potential misuse has only increased. In a detailed safety report, Anthropic has revealed how countries and groups are trying to misuse Claude, including incidents of espionage, mass surveillance, and bioweapons.
In the report, Anthropic goes through a series of attempts which it managed to disrupt between December 2025 to August 2026. As per the company, the cases involved suspected state-backed groups, financially motivated criminals, propaganda networks, spyware vendors, and politically driven actors.
Claude Haiku, Sonnet and Opus models were used in the cases the company outlined. Anthropic said none of the misuse cases involved Claude Fable or Mythos-class models, except for one distillation case. It said the examples were not typical misuse, but the most notable and novel threat activity it had identified to date.Using Claude for bioweapons?
Anthropic explained that the most sensitive cases involved biological research by working scientists, including some it described as state-supported users, because it could not always determine whether their work was legitimate or intended for harm.
Anthropic stated that it chose to proceed with caution, arguing that valid biological research can overlap with work that could help create dangerous pathogens. “You are not seeing someone in a comic book kind of way say, ‘Hey, I want to build a biological weapon to kill everybody,’” Jacob Klein, Anthropic’s head of threat intelligence, said in an interview. “It’s an incredibly nuanced situation.”
Anthropic documented five biological misuse case studies. In one case from May, a scientist sought help drafting a grant application for gain-of-function research on the chikungunya virus, a mosquito-borne illness that can lead to severe pain and other symptoms for months. The company explained the proposed research involved engineering mutations that would make the virus more harmful as it repeatedly infected live animals. Anthropic said the request was troubling in part because it believed the work was intended for a military research institute.
As per Anthropic, the case was blocked by its biological safety classifier, but that the user then routed around the control through a third-party evasion platform that later added a fallback to a competitor’s model when Claude would not comply.
In another case, Anthropic revealed that a reseller relay serving unrelated customers allowed one user to draft an orthopoxvirus immune-evasion grant application from start to finish on Opus 5 in about an hour. Orthopoxvirus is a family of viruses that causes human illness, including smallpox. In a separate case, a researcher planning avian flu mammalian-adaptation experiments over several weeks was confined to Anthropic’s weakest model tier throughout.
Anthropic also disrupted two state-backed venom or toxin redesign programmes and, in a 30-day sweep of state-linked activity, found about 35 distinct research efforts, most of them legitimate civilian science but some dual-use. “We do not assert that they intended harm, and identifying them or their labs could expose them to harm,” the company wrote.
Anthropic said the users had circumvented controls designed to block access from countries where Claude is unavailable and had tried to obscure the purpose of their research. The company banned the accounts and, in biological cases, relied not only on bans but also on hard refusals, downgrading to weaker model tiers and proactive sweeps.State-linked groups trying to make weapons with AI
Apart from biological weapons, Anthropic says, they also found attempts to use The Claude to develop software for conventional weapons, including firearms, missiles, armed drones and bombs. As per the company, it spotted three cases in China, two in Russia and one in Yemen.
In the Yemeni case, the company said a cell of bad actors used Claude Code in place of human guidance, navigation and control engineers while developing software for a guided rocket, a multistage ballistic missile intended to exceed 2,000 kilometres in range and a hypersonic glide vehicle variant. Anthropic said the group test-fired the guided rocket and that the field test appeared to have failed.
In Russia, Anthropic found a freelance operator, linked to an effort called DronDoc or Serafim, using Claude Code to engineer a full-stack autonomous first-person-view kamikaze drone swarm. The company said the onboard model could select targets, including a “person” class, and detonate without a human in the loop, using vision training from scraped Ukrainian combat footage.
In China, Anthropic said an account it described as potentially linked to the military-industrial sector used Claude to build a 16-module electronic warfare and air-defence suppression suite. It said the user later shifted the simulation from a generic scenario to 12 real targets in Taiwan, including a command bunker and Patriot and Tien Kung batteries.Anthropic says China and Iran tried using Claude for surveillance
Weapons are not the only area of focus for those looking to misuse AI tools like Claude. It seems that many groups want to use AI to run mass surveillance operations. Anthropic recorded nine such instances. In one case, a group with suspected links to China used Claude to track, profile and recruit Uyghur populations and journalists with ties to the Syrian Army. The company said the operation used bulk data from monitored WhatsApp and Telegram chats to build profiles, and Claude was also used for real-time translation and role-playing to test deception.
Anthropic also described China-based surveillance activity targeting Catholic cardinals, the Presbyterian Church in Taiwan, Tibetan Buddhists and Falun Gong. It said one actor re-prompted after an initial refusal and obtained suppression guidance naming 10 private citizens, as well as pre-operational intelligence on overseas protests.
In Iran, Anthropic said two linked units using 16 Claude accounts claimed to have surveilled or profiled 6,388 Iranians over a year, analysed 155,216 tweets to identify 39 opposition accounts and used a malicious Firefox extension to harvest identities into a shared case-management system called Arman. The company said an Iran-linked actor also used Claude to identify US naval targets. Anthropic said its usage policy bars non-consensual surveillance and profiling.Using Claude for espionage
On cyber operations, Anthropic said AI had enabled groups to automate reconnaissance, exploitation and monitoring. One Russian-speaking actor used Claude in attacks on more than 20 Ukrainian and European government, defence and diplomatic targets and on drone manufacturers. As per Anthropic, the person stole a complete drone vision-system software development kit, hijacked hotel WiFi domain name system records to plant malware on the devices of guests. The person then took over officials’ WhatsApp accounts by suppressing read receipts and obtained more than 300,000 national identity records and more than 500,000 company registry entries from a North African government body.
The company said AI-based monitoring agents detected when security products flagged the malware and autonomously rewrote it until it evaded detection again. Anthropic said it banned the accounts, built new detections around behavioural signatures and coordinated with Microsoft, whose own reporting on the hotel WiFi technique supported the finding.
Another China-linked group, including two university students, was said to have used parallel AI workstreams for firmware reverse engineering, open-source intelligence on foreign governments and scheduled intelligence collection, compromising about 50 organisations globally.
In influence operations, Anthropic found groups using Claude both to plan campaigns and to generate the false or misleading content itself. The company says it disrupted at least nine such efforts involving Russia, China, Iran, Bangladesh and Kenya, and that the broadest authentic reach came where state media acted as the distribution channel, including radio and television.
Among the cases highlighted were Russian state-media insiders, including a former Sputnik Moldova editor-in-chief, who used Claude as a sub-editor to produce material for Sputnik Moldova. Anthropic also said a Russian-speaking co-ordinator in Bangui used Claude for Radio Lengo Songo, a Wagner-founded station, to generate pro-Russia and anti-France content, forge Central African Republic government documents and produce human resources paperwork. The company said Claude refused one request to name real people as militants for security action.Data breaches and fake dating site
Another misuse of Claude was by financially motivated groups. In one case linked to ShinyHunters affiliates, the company found operators downloaded 1.8 million Android application packages and scanned them for hardcoded secrets, feeding a Telegram-based carding operation. Related breaches included more than 1TB of stolen data from a technology provider, tens of millions of airline passenger records and a software supply-chain breach.
Anthropic said that in April 2026 it detected a China-based network of more than 20 dating applications marketed as “fully human”, but powered largely by Claude-driven personas. During a two-week period, it said it identified more than 4,700 or nearly 5,000 AI personas, depending on the count used in the report, which sent 2.36 million messages to at least 25,000 real users. Anthropic said the network mixed AI personas with gig workers at roughly a three-to-one ratio and instructed the personas never to reveal they were automated. The company said it banned the accounts and organisations involved.Rivals distilling Claude
So far, we have discussed cases linked to countries or bad actors, but Anthropic has also listed incidents where it found rival AI companies using Claude. Anthropic stated that competing AI firms and related networks had tried to use Claude outputs to train their own models, a category it called illicit distillation.
It named campaigns linked to Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax. Anthropic said the largest measured campaign, which it attributed to Alibaba, reached nearly three million exchanges a day at its peak and more than 151 million exchanges between May and July 2026 through more than 3,500 fraudulent accounts.
Moonshot AI, the company behind the Kimi K3 AI model, silently forwarded about 300,000 customer requests to Claude over 10 days, while DeepSeek used a similar replay technique for 12.1 million exchanges in 14 days.
Anthropic responded by banning accounts, tracing proxy networks hiding behind resellers, hardening extraction classifiers, summarising internal reasoning in outputs, introducing a “preserved thinking” feature and requiring identity verification for accounts showing abuse signals.
Anthropic said that across all seven harm areas it removed accounts, strengthened safeguards and, where appropriate, shared intelligence with authorities, researchers, industry partners and victims. The company added that it was publishing the report because misuse would grow as models became more capable unless developers and defenders acted to make them safer, and that the findings should help other platforms recognise similar patterns and improve collective defences.- EndsPublished By: Armaan AgarwalPublished On: Sep 11, 2026 09:11 ISTAlso Read | iPhone inflation is real: iPhone 18 Pro series is more expensive, how much is this increase?Also Read | Nvidia CEO Jensen Huang claims GPT-6 Astra is AGI, experts say not quiteAlso Read | Explained: OpenAI solves 90-year-old maths problem humans could not, so why is everyone angry at Sam Altman


