Anthropic7 mins read

Anthropic report details Claude abuse in cyberattacks, weapons work, surveillance and AI training data extraction

A new Anthropic threat intelligence report says Claude was misused over eight months for espionage, malware iteration, surveillance platforms, weapons software and unauthorized model distillation by Chinese AI labs.

Anthropic says Claude misuse spanned eight months and seven risk areas

Anthropic cybersecurity image
Image credits:Nano Banana Pro prompted by THE DECODER

Anthropic’s threat intelligence report covers December 2025 through August 2026 and groups misuse into cyber operations, influence operations, surveillance, fraud, biological misuse, conventional weapons and unauthorized model distillation. The report says Haiku, Sonnet and Opus were the most affected Claude models, while newer Fable and Mythos models appeared in only a single distillation case. The central takeaway for readers is that AI misuse is no longer limited to simple prompt abuse: models are being inserted into operational workflows where speed, scale and automation matter.

Cyber cases show AI lowering the cost of attacks

The report’s cyber chapter argues that sophisticated attacks no longer require sophisticated attackers, because reconnaissance, exploitation and tool-building can be handed off to models running in parallel. Anthropic describes a Russian-speaking espionage actor that used AI agents to test malware against security products, then rewrite and recompile it when antivirus tools detected it. The practical implication for defenders is clear: static signatures and slow update cycles become less effective when attackers can iterate at machine speed.

Chinese AI labs allegedly extracted Claude data or routed customers through it

Anthropic identifies multiple Chinese AI labs in unauthorized distillation or request-routing campaigns, including Alibaba’s Qwen team, DeepSeek, Moonshot AI, Xiaomi, Zhipu, SenseTime and MiniMax. The largest campaign attributed to Alibaba’s Qwen lab totaled more than 151 million exchanges between May and July 2026, according to the report. Anthropic also says some labs relayed their own users’ requests to Claude, creating cases where sensitive material such as surveillance data, public security work and personal information passed through the system.

Weapons, surveillance and biology raise harder governance questions

The report says Claude was used in conventional weapons-related cases, including missile guidance software, an autonomous FPV kamikaze drone swarm and electronic warfare modules. In surveillance, Anthropic describes a Mali project called “Lakana 360” that used Claude as a primary engineering workforce for a platform monitoring roughly 25 million SIM cards across all three national mobile carriers. The biology section is more self-critical: Anthropic says classifiers struggle in dual-use science because legitimate and harmful intent can be nearly impossible to distinguish, and the company points to stricter safeguards and verified-user access as responses.

Discover More

    OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei
    AI Slowdown Debate

    Top AI figures are backing a frontier AI slowdown, while critics warn about regulation, transparency, and open-source risks.

    AIAnthropic
    Illustration for The Decoder article on Anthropic CEO Dario Amodei and AI speed limits
    Amodei Calls for AI Speed Limits

    Anthropic’s CEO wants auditors, shared safety standards, and global agreements before AI self-improvement accelerates further.

    AI SafetyAnthropic