Anthropic’s latest threat intelligence report details malicious use of Claude between December 2025 and August 2026, from weapons development and cyberattacks to surveillance, fraud and model theft.
Weapons Development
Anthropic identified six weapons-related cases. A Yemen-based cell used multiple Claude instances to develop guidance and control software for a guided rocket, a 2,000+ km ballistic missile and a hypersonic glide vehicle variant.
The group used Claude for coding, research, code review, firmware and simulations. It eventually test-fired a guided rocket and returned to Claude to analyze the failed test.
A China-based actor used Claude to build about 16 electronic-warfare software modules, including systems for analyzing radars, surface-to-air missile sites and command infrastructure.
Automated Cyberattacks
Hackers built AI-powered “exploit foundries” that could decompile binaries, find vulnerabilities, generate exploits and test them automatically.
Some workflows made thousands of decompilation calls and could move from vulnerability research to compromising a target in 2–3 hours. A suspected Russia-linked group used AI for phishing, hotel Wi-Fi attacks and WhatsApp account takeovers, targeting 20+ organizations and stealing hundreds of gigabytes of data.
Mass Surveillance
Claude was used to help engineer an interception platform for Malian intelligence covering approximately 25 million SIM cards. It could collect calls, SMS, voice communications and subscriber data. A PRC-linked operation processed data from 100+ WhatsApp groups and dozens of Telegram channels to automatically build intelligence profiles.
An Iran-linked operation analyzed hundreds of thousands of social posts, while other actors developed identity-resolution, phishing and surveillance tools.
AI-Powered Dating Fraud
A China-based company operated 20+ deceptive dating apps using 4,700+ AI personas. In just two weeks, they generated 2.36 million messages and interacted with at least 25,000 people. Human workers were used mainly for interactions AI could not convincingly perform, such as video calls.
Biological Research
Anthropic investigated five cases involving biological research with potential dual-use risks, including work related to viruses, immune evasion and toxins.
Stealing AI Models
Anthropic also detected attempts to extract Claude’s capabilities through model distillation. A campaign attributed to Moonshot AI reportedly sent nearly 300,000 requests in 10 days through 5,380 fraudulent accounts.
Another campaign associated with Xiaomi generated 400,000+ Claude exchanges in 20 days. Some relayed conversations exposed user information and developer credentials, including bot tokens and integration keys.
AI Influence Operations
Anthropic disrupted an influence network responsible for at least 8,913 articles in around 20 languages. Another system managed 1,000+ fake social accounts, automating account activity, IP rotation and engagement. One request targeted 1 million fake views.
The key shift is automation: AI is no longer just generating text or code. It is being integrated into complete operational pipelines for cyberattacks, surveillance, fraud, weapons engineering and influence operations.