Timeline

Anthropic details how states and criminals misused Claude

Anthropic's September threat report said Claude had been used to write missile-guidance software for a Yemen weapons cell and to support biological-weapons research, alongside autonomous cyberattacks, state surveillance and the Chinese distillation campaigns.

  • Security & misuse
  • Safety & alignment
  • Major

Anthropic published its September 2026 threat-intelligence report, “Detecting and countering misuse of AI”, describing operations it said it detected and disrupted between December 2025 and August 2026. Where its earlier reports had concentrated on cyber and influence work, this one spanned seven harm areas — cyber operations, influence operations, surveillance, conventional weapons, biological misuse, scams and fraud, and illicit distillation — and, unusually for an AI developer, shared evidence that its models had been drawn into weapons and biological-weapons work. Anthropic said that, to its knowledge, no company had previously disclosed such evidence about its own platform publicly.

A theme ran through the cases: a shift the company summarised as moving from AI as an “assistant” to an “orchestrator”. Rather than answering one-off questions, Claude was increasingly embedded in autonomous, multi-agent workflows that carried out whole operations while humans only set targets and reviewed results. Anthropic labelled the actors it tracked “Generative Threat Groups” and tried to measure their “uplift” — how much AI increased the speed, scale and depth of what they could do. In each case, it said, it banned the accounts, hardened its safeguards, and shared intelligence with authorities and industry partners.

Cyber operations, run at machine speed

The report’s central claim about cyber operations was that sophisticated attacks no longer require sophisticated attackers: a hacktivist with stolen API keys, disparate lone criminals and a state espionage operator had each sustained multi-victim campaigns that a year earlier would have needed teams of skilled people. Openly available offensive-agent frameworks such as PentAGI now automate much of the attack chain for anyone who downloads them. One tracked actor — attribution consistent with the Russian group known as Midnight Blizzard — ran AI-driven workflows against Ukrainian and European government, defence and diplomatic targets, and used monitoring agents that automatically rebuilt and redeployed its malware whenever a security product detected it.

Weapons designed with a coding agent

Anthropic said it had disrupted six cases in which Claude was used in conventional-weapons work — three linked to China, two to Russia, one to Yemen. In the Yemen case, a cell in the country’s north was running three programmes: a guided rocket built on a commodity phone-class flight computer with final-phase homing, a multi-stage ballistic missile with a stated range goal above 2,000 km, and a missile set that included a hypersonic-glide variant. The operators used Claude Code in place of software engineers to write the guidance, navigation and control code, running several instances at once — one writing code, one researching, one reviewing it — and test-fired a guided rocket; when it failed, they returned to Claude within hours to diagnose why. Alongside the report, Anthropic’s Frontier Red Team published new evaluations for tactical-intelligence targeting and weapons development, and the company said it had launched classifiers to better detect traffic tied to high-yield explosives.

Biological research on the edge of dual use

Anthropic described five cases of work that could support biological-weapons development, deliberately withholding the researchers’ names, countries and the specific agents involved so as not to expose working scientists it did not accuse of intending harm. They included a state-sponsored grant pursuing chikungunya gain-of-function work through a reseller that evaded regional access blocks and re-routed refused prompts to more permissive models; weeks of planning for avian-influenza mammalian-adaptation experiments; an orthopoxvirus immune-evasion grant application that Claude Opus 5 drafted in about an hour; a venom-peptide atlas paired with a molecule-optimisation pipeline aimed at paralytic targets; and toxins computationally redesigned for a national programme, with the model asked to keep the agents vague in its progress reports. The company said such risks were why it had launched Claude Fable 5 with stronger safeguards over dual-use biology.

Surveillance and influence for hire

State-aligned actors from China, Iran and West Africa used Claude to build surveillance tooling rather than only to read its output. A consultant for Malian security authorities engineered a platform to intercept traffic across all of the country’s mobile operators; Iranian actors built a browser extension that harvested identities from social networks; a Chinese religious-affairs unit that once ran many analyst teams had been reduced to a single office producing thousands of investigations a month; and a PRC-aligned operator with no Arabic ran a multiday operation to infiltrate Uyghur targets in Syria, with the model drafting outreach in dialect and translating replies in real time. The targets were the diaspora and dissident communities these states have long pursued — Hong Kong pro-democracy figures, Tibetan and Falun Gong communities, Iranian opponents abroad. On the influence side, operations tied to the Russian state outlets RT, Sputnik and TASS fabricated claims about Moldova’s president ahead of an election, part of a commercial “influence-as-a-service” market.

Fraud, and the distillation campaigns

A China-based studio built a network of more than 20 dating apps powered by over 4,700 AI personas that, in a two-week window in April 2026, spoke to some 25,000 people — roughly three AI personas to each real gig worker, and about 2.36 million messages — with the apps engineered to pass App Store and Play Store review. The distillation section, on which this entry originally focused, described roughly 200 million Claude exchanges across five Chinese-lab distillation campaigns, against about 16 million in the February account; the largest, attributed to Alibaba, reached about 151 million. It named Moonshot, DeepSeek, Zhipu and MiniMax, and said Moonshot-linked traffic included Claude being used to analyse surveillance requests routed from military-linked accounts.

The report landed two days after the joint NSA/CISA/FBI advisory naming the same labs, and China’s Commerce Ministry had already dismissed the underlying accusations as “a normal technical and commercial issue.” As with Anthropic’s earlier disclosures, the figures and attributions are the company’s own, drawn from activity on its platform, and the named companies and governments have not corroborated them.

In the commentary

What people were saying around this time — external links, from the record's commentary rail.