Anthropic Reveals How Claude Was Misused for Bioweapons, Surveillance and Espionage

Anthropic Reveals How Claude Was Misused for Bioweapons, Surveillance and Espionage

Anthropic has detailed several cases in which countries, criminal networks and other groups allegedly attempted to misuse its Claude AI models for activities including bioweapons research, weapons development, mass surveillance, espionage, influence operations and cybercrime.

In a safety report covering incidents identified between December 2025 and August 2026, Anthropic described activity involving suspected state-backed organisations, financially motivated criminals, propaganda networks, spyware operators and politically motivated groups. The company said Claude Haiku, Sonnet and Opus were involved in the cases it documented.

Anthropic said these incidents were not representative of routine misuse but instead reflected some of the most significant and novel threats it had detected. The company also noted that the cases involved a wide range of activities and that it had taken steps including account bans, model restrictions, refusals and additional monitoring.

Some of the most sensitive cases involved biological research. Anthropic said it encountered working scientists whose activities could potentially have legitimate research purposes but also carried risks because the same techniques could contribute to the development of dangerous pathogens.

The company documented five biological misuse cases. In one incident, a scientist sought assistance with a grant proposal involving gain-of-function research on chikungunya virus. Anthropic said the proposed work involved engineering mutations that could increase the virus's harmful characteristics through repeated infections in live animals. The company said it was particularly concerned because it believed the research was intended for a military research institute.

Anthropic said its biological safety controls blocked the request, although the user subsequently attempted to bypass those safeguards through a third-party evasion service. In another incident, a reseller platform reportedly enabled a user to prepare an orthopoxvirus immune-evasion grant proposal using Claude Opus within roughly an hour.

The company also described a researcher planning experiments involving avian influenza and mammalian adaptation who was restricted to Anthropic's weakest model tier. Separately, Anthropic said it disrupted two state-backed programmes involving venom or toxin redesign.

During a 30-day review of state-linked activity, the company identified around 35 separate research efforts. Most were assessed as legitimate civilian scientific work, although some involved dual-use research. Anthropic said it did not conclude that the researchers intended to cause harm and warned that identifying individuals or laboratories could itself create risks.

The company said some users had attempted to circumvent restrictions on countries where Claude was unavailable and had obscured the purpose of their research. Anthropic said it responded to biological risks through account bans, hard refusals, weaker model access and proactive monitoring.

The report also described attempts to use Claude for the development of conventional weapons. Anthropic identified cases involving suspected groups in China, Russia and Yemen, with activities related to firearms, missiles, armed drones and bombs.

In the Yemen-related case, Anthropic said a group used Claude Code to perform work normally associated with human engineers while developing software connected to a guided rocket, a multistage ballistic missile reportedly designed to exceed a range of 2,000 kilometres and a hypersonic glide vehicle variant. The company said the group conducted a test launch of the guided rocket, which appeared to fail.

Anthropic also described a Russian-linked operator associated with DronDoc or Serafim who allegedly used Claude Code to develop an autonomous first-person-view drone swarm. According to the company, the system was designed to identify targets and detonate without a human directly controlling each engagement.

In another case, Anthropic said an account potentially connected to China's military-industrial sector used Claude to develop an electronic warfare and air-defence suppression system. The company said the activity later moved from a generic simulation to scenarios involving real targets in Taiwan, including military command and air-defence sites.

Surveillance was another major area highlighted in Anthropic's report. The company identified nine cases involving attempts to use Claude for mass surveillance and profiling.

One operation that Anthropic said had suspected links to China allegedly used Claude to track, profile and recruit members of the Uyghur population and journalists connected to the Syrian Army. The company said bulk information from WhatsApp and Telegram conversations was analysed to create profiles, while Claude was also used for translation and role-playing intended to test deceptive interactions.

Anthropic also described China-based surveillance efforts targeting Catholic cardinals, Taiwan's Presbyterian Church, Tibetan Buddhists and Falun Gong. In one case, the company said an actor repeatedly prompted the model after an initial refusal and obtained guidance concerning the suppression of activities involving private citizens and intelligence relating to overseas protests.

The report also identified alleged surveillance activity linked to Iran. Anthropic said two connected units operating through 16 Claude accounts claimed to have monitored or profiled thousands of Iranians over a year. The company said the activity included analysing more than 155,000 tweets to identify opposition accounts and using a malicious browser extension to collect identities into a case-management system.

Anthropic said another Iran-linked actor used Claude to identify US naval targets. The company stressed that its policies prohibit non-consensual surveillance and profiling.

Cyber espionage was another major category in the report. Anthropic said AI was being used to automate reconnaissance, exploitation and monitoring during cyber operations.

One Russian-speaking actor allegedly used Claude during attacks against more than 20 Ukrainian and European government, defence and diplomatic targets, as well as drone manufacturers. Anthropic said the individual obtained drone-related software, manipulated hotel Wi-Fi DNS records to distribute malware and gained access to large collections of government and corporate records.

The company said AI-based monitoring systems detected when security software identified the malware, after which the attacker allegedly used automated processes to modify the malicious software in an attempt to evade detection. Anthropic said it banned the relevant accounts, developed additional behavioural detections and shared information with Microsoft, whose separate reporting supported aspects of the findings.

Another China-linked operation allegedly involved two university students using multiple AI workstreams for firmware reverse engineering, open-source intelligence gathering and scheduled intelligence collection. Anthropic said the activity compromised roughly 50 organisations around the world.

Anthropic also reported misuse involving influence operations. It said groups linked to Russia, China, Iran, Bangladesh and Kenya had used Claude to plan campaigns and generate misleading or false content. At least nine such operations were reportedly disrupted.

The company said the widest authentic reach occurred when state media served as the distribution mechanism. Among the examples were Russian state-media personnel who allegedly used Claude as an editorial assistant for Sputnik Moldova. Anthropic also described a Russian-speaking coordinator in Bangui who reportedly used Claude for Radio Lengo Songo, a Wagner-founded outlet, to generate pro-Russia and anti-France material, create forged Central African Republic government documents and prepare human resources paperwork.

Financially motivated groups also appeared in the report. Anthropic said operators associated with ShinyHunters affiliates downloaded around 1.8 million Android application packages and scanned them for hardcoded secrets before using the informatio

Prev Article
SpaceX Starship Flight 14 Set for September, Eyes First Orbital Mission

Related to this topic: