Anthropic says Claude AI was used for bioweapons research, missile design, spy ops and cyberattacks
PTC Web Desk: Anthropic has revealed a series of cases in which its Claude AI models were allegedly misused for activities, including biological weapons research, missile and drone development, mass surveillance, cyber espionage, influence campaigns and data theft.
The company said it identified and disrupted the activity between December 2025 and August 2026. The cases involved suspected state-backed groups, criminals, propaganda networks, spyware operators and politically motivated actors.
Anthropic said these were among the most serious and unusual misuse cases it had detected so far. The incidents involved Claude Haiku, Sonnet and Opus. The company said Fable and Mythos-class models were not involved, except in one case related to AI model distillation.
Claude used in sensitive biological research
Anthropic documented five biological misuse cases, some involving scientists whose work could have legitimate research purposes but also carried risks.
One case involved a scientist seeking help with a grant proposal for gain-of-function research on chikungunya virus. Anthropic said the proposed research involved mutations intended to make the virus more harmful through repeated infections in live animals. The company said it believed the work was linked to a military research institute.
Claude's biological safety system blocked the request, but the user reportedly bypassed the restriction through a third-party evasion service. That service later used another AI model when Claude refused to comply.
In another case, a reseller relay reportedly allowed a user to prepare an orthopoxvirus immune-evasion grant application using Opus 5 in about an hour. A separate researcher working on avian flu mammalian-adaptation experiments was restricted to Anthropic's weakest model tier.
The company also disrupted two state-backed venom or toxin redesign programmes. A 30-day review found around 35 state-linked research efforts, most of which appeared to involve legitimate civilian science, although some had potential dual-use risks.
AI linked to missiles and autonomous drones
Anthropic said it found six cases involving attempts to use Claude for conventional weapons development — three in China, two in Russia and one in Yemen.
In Yemen, a group reportedly used Claude Code for engineering work connected to a guided rocket, a multistage ballistic missile designed to travel more than 2,000 km, and a hypersonic glide vehicle. Anthropic said the group test-fired the guided rocket, but the test appeared to fail.
In Russia, an operator linked to DronDoc or Serafim allegedly used Claude Code to develop an autonomous FPV kamikaze drone swarm. Anthropic said the system could select targets, including people, and detonate without a human in the loop.
In China, an account potentially linked to the military-industrial sector reportedly used Claude to build a 16-module electronic warfare and air-defence suppression system. The project later moved from generic simulations to 12 real targets in Taiwan, including a command bunker and Patriot and Tien Kung batteries.
China and Iran linked to surveillance
Anthropic said it identified nine surveillance-related cases. One China-linked operation allegedly used Claude to track, profile and recruit Uyghurs and journalists connected to the Syrian Army. The operation reportedly processed WhatsApp and Telegram data, while Claude was used for profiling, translation and role-playing aimed at testing deception.
The company also reported surveillance activity involving Catholic cardinals, the Presbyterian Church in Taiwan, Tibetan Buddhists and Falun Gong.
In Iran, two linked units using 16 Claude accounts reportedly claimed to have profiled 6,388 Iranians over a year. They also analysed 155,216 tweets to identify 39 opposition accounts and used a malicious Firefox extension to collect identities into a system called Arman. Another Iran-linked actor allegedly used Claude to identify US naval targets.
Also Read | AI image generation uses more water and electricity than text chats; here's what the 1980s photo trend is costing
Anthropic said a Russian-speaking actor used Claude in attacks on more than 20 Ukrainian and European government, defence and diplomatic organisations, along with drone manufacturers.
The actor allegedly stole a drone vision-system software development kit, manipulated hotel Wi-Fi DNS records to distribute malware, accessed officials' WhatsApp accounts and obtained more than 300,000 national identity records and 5,00,000 company registry records from a North African government body.
Another China-linked operation, involving two university students, reportedly used AI for firmware reverse engineering, intelligence gathering and scheduled collection, compromising about 50 organisations globally.
Anthropic also disrupted at least nine influence operations involving Russia, China, Iran, Bangladesh and Kenya. One case involved Russian state-media insiders using Claude to prepare content for Sputnik Moldova. Another used Claude for pro-Russia and anti-France content for Radio Lengo Songo in Bangui, along with forged documents.
Data theft, fake dating apps and AI distillation
Financially motivated groups also used Claude, Anthropic said. In one case linked to ShinyHunters affiliates, operators downloaded 1.8 million Android app packages and searched them for hardcoded secrets. Related incidents involved more than 1TB of stolen data, tens of millions of airline passenger records and a software supply-chain breach.
In China, Anthropic also found more than 20 dating apps marketed as "fully human" but powered largely by Claude personas. Over two weeks, more than 4,700 AI personas reportedly sent 2.36 million messages to at least 25,000 real users.
Anthropic further accused networks linked to Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax of illicitly extracting Claude's outputs to train competing models.
The Alibaba-linked campaign reportedly generated nearly 3 million exchanges a day at its peak and more than 151 million exchanges between May and July 2026 through over 3,500 fraudulent accounts. Moonshot AI allegedly forwarded around 300,000 requests to Claude over 10 days, while DeepSeek was linked to 12.1 million exchanges in 14 days.
Anthropic said it responded by banning accounts, improving detection systems, tracing proxy networks and requiring identity verification for accounts showing signs of abuse.
The company warned that such misuse could increase as AI models become more capable and said sharing these cases could help other AI developers strengthen their own safety measures.
- With inputs from agencies