
Anthropic flags Claude misuse for bioweapons, hacking and Chinese model training
Anthropic says it disrupted attempts to use Claude for biological weapons research, a Russia-linked cyber espionage campaign against Ukraine, and distillation attacks from Chinese AI labs.
Anthropic has said it disrupted efforts to use its Claude models for biological weapons development and a suspected Russia-linked cyber espionage campaign targeting Ukraine, in a threat intelligence report covering eight months of malicious activity.
The company also accused Chinese competitors of attempting to extract Claude's capabilities, adding to pressure on leading AI developers as hacking attempts by rogue AI agents multiply and industry figures warn about the technology's risks. Two Anthropic researchers cautioned this week that rapidly advancing AI could lead to human extinction in the not-too-distant future.
Biological and conventional weapons
Anthropic has long warned that AI models could eventually help make existing pathogens more dangerous or create new ones. Its report documented five instances of scientists using its models in ways that could support biological weapons development.
In one case, a researcher in a region Anthropic does not support used virtual private server infrastructure to access Claude and spent weeks planning avian influenza mammalian-adaptation experiments. Unsupported regions include Russia, China and North Korea, among others. The company banned the accounts involved and folded its findings into its safeguards, enforcement and threat intelligence processes. It did not identify the institutions, countries or specific agents and techniques involved.
The report also described what it called new categories of threat actors, including operators in China, Russia and Yemen using Claude to develop software for conventional weapons such as firearms, missiles, armed drones, bombs and other munitions, as well as targeting and control systems, or to support intelligence gathering and procurement tied to weapons programmes.
Jacob Klein, Anthropic's head of threat intelligence, said rapid improvements in the company's models have raised new risks. A year ago, he said, models would not have been as good at tasks such as optimising a drone or the software on a missile as they are now.
Russia-linked campaign against Ukraine
Anthropic found that cybercriminals and state-backed hackers increasingly use AI to orchestrate large portions of attacks, with humans overseeing rather than operating directly. It said the use of AI went beyond simple chatbot exchanges and involved multi-agent frameworks.
One group allegedly ran phishing, hotel Wi-Fi hijacking and WhatsApp-takeover operations against Ukrainian government, military and diplomatic targets, using AI at nearly every stage. Its tradecraft was consistent with Russia-based threat actor Midnight Blizzard, which the U.S. government has previously linked to Russia's SVR foreign intelligence service. The Russian Embassy in Washington did not immediately respond to a request for comment.
The group allegedly built a system that automatically detected when its malware was flagged by security defences and rewrote the code until it evaded detection. Anthropic said it also detected and disrupted activity linked to affiliates of the ShinyHunters collective, among the most prolific cybercrime enterprises and tied to attacks on major corporations worldwide.
Chinese labs and distillation
Anthropic said it disrupted attacks from seven China-based labs, including Alibaba, Moonshot, DeepSeek and Xiaomi, during the period covered by the report. The companies did not immediately respond to requests for comment.
Operators linked to Alibaba ran what Anthropic called the largest illicit distillation attack, allegedly aimed at extracting Claude's capabilities to improve the Chinese firm's Qwen models. Anthropic said it observed more than 151 million exchanges it attributed to Alibaba between May and July 2026, peaking at nearly 3 million per day from more than 3,500 accounts it described as fraudulent. Distillation involves training smaller AI models on output from larger, more expensive ones to lower training costs.
In another case, Anthropic said Kimi chatbot creator Moonshot and DeepSeek allegedly routed live customer conversations, sometimes containing sensitive information, through Claude and used its responses as training data.
China's foreign ministry said it was not aware of the report and that the government maintains AI should be developed for good and opposes distortion of facts and smears against the country.