Anthropic: The Report That Implicates Claude, Between Missiles, Espionage in Mali, and Chinese Pillaging
One tool, two faces. Between December 2025 and August 2026, Russian spies, Chinese hackers, and a Malian consultant had the same idea. Several Chinese AI laboratories did too. All employed Claude for their purposes, without asking for permission from anyone. Anthropic has just released the report detailing how. And especially, how the company claims to have disconnected each of these operations, one by one. Key points of this article:
- Anthropic discovered that its AI, Claude, was exploited by Russian spies, Chinese hackers, and a Malian consultant for cyberattacks and data theft.
- Claude was used for weapon programs in China, Russia, and Yemen, as well as for illegal surveillance operations and romance scams in Africa.
Cyberattacks: Claude Code Hired by Moscow and Beijing {#h-cyberattacks-claude-code-hired-by-moscow-and-beijing}
The official report from Anthropic documents the group GTG-20006, linked to the Russian collective Midnight Blizzard. Its target: over 20 government and military organizations in Ukraine, Europe, and the Middle East. Indeed, autonomous AI agents were rewriting malware in real-time as soon as an antivirus detected them. Furthermore, over 300,000 national identity files were stolen in North Africa.
In Changsha, Hunan, two undergraduate students and a former intern from a Chinese cybersecurity firm set up a nearly autonomous exploit factory. It targeted around fifty organizations, from energy to health. Meanwhile, hackers affiliated with ShinyHunters used Claude agents to scan 1.8 million Android applications. The goal: to uncover exposed secrets.
Moreover, a technology provider left several terabytes of data behind, according to Anthropic. Anthropic also acknowledges that, in some operations, AI agents did << almost all the work >> on their own, without continuous human supervision.
Weapons and War: Claude Targets Taiwan and Arms Yemen {#h-weapons-and-war-claude-targets-taiwan-and-arms-yemen}
According to Anthropic, six conventional weapon programs mobilized Claude: three in China, two in Russia, and one in Yemen. A Yemeni cell reportedly preferred AI over human engineers to work on a missile project. It even went so far as to ask it to diagnose the failure of a test.
On the Russian side, another case would involve a drone project. On the Chinese side, another would concern a simulation of electronic warfare targeting sites in Taiwan. Anthropic claims to have also documented five cases related to research on biological weapons, without detailing their nature.
We're publishing our most detailed threat intelligence report to date.
It covers how people tried to misuse Claude---for cyberattacks, influence operations, surveillance, biology, and building weapons---and how we found and stopped them.
We disrupted every operation in the report,...
--- Anthropic (@AnthropicAI) September 10, 2026
<< We are publishing our most detailed threat monitoring report to date.This report describes how Claude was misused -- for cyberattacks, influence operations, surveillance, biology, and weapon design -- and how we detected and neutralized these attempts.
We thwarted all operations mentioned in the report and learned from these experiences to strengthen our protective measures. Where appropriate, we also shared our findings with authorities and other AI-specialized companies.
These cases are exceptional: we highlight some of the most sophisticated misuses we have observed. However, it is essential to analyze them, as they indicate trends in AI misuse, strengths, and areas for improvement in our protective measures.
We publish this report so that others can identify the same activities on their own platforms and so we can provide the public with a clearer view of the evolution of emerging threats.>>
Surveillance and Romance Scams: The True Face of Misused Claude {#h-surveillance-and-romance-scams-the-true-face-of-misused-claude}
In Bamako, a consultant working for the National State Security Agency (ANSE) built a system with Claude. Named Lakana 360, it monitors around 25 million SIM cards across the country's three mobile operators. The program includes: calls, messages, voice interception, and automated intelligence files. This system also bypasses the legal requirement for a court decision. Another detail that worries Anthropic: it operates locally. Banning the consultant's account is therefore not enough to stop it.
More trivial, but just as organized: the GTG-15001 network ran over 4,700 AI personas on 20 dating apps. The goal: at least 25,000 real people targeted in two weeks. Consequently, nearly 2.36 million messages were generated, with a ratio of three fake profiles per real victim. When someone requested a video call, freelance workers took over to make the scam credible.
-- Price
Chinese Distillation: AI Labs Tap into Claude {#h-chinese-distillation-ai-labs-tap-into-claude}
This is the section that should interest Washington the most. Seven Chinese laboratories have siphoned off Claude's reasoning to strengthen their own models. This technique is called distillation.
Alibaba at the Top of the List {#h-alibaba-at-the-top-of-the-list}
Alibaba is far ahead, with over 151 million exchanges between May and July. The daily peak reached nearly 3 million exchanges. More than 3,500 fraudulent accounts did the work, all focused on the Qwen model family.
This is indeed a clear escalation compared to the episode that Le Journal du Coin reported back in June. At that time, Anthropic estimated the misuse at 28.8 million exchanges earlier in the year.
Moonshot and DeepSeek, the Same Scheme
Moonshot AI has totaled over 23 million exchanges. Anthropic claims to have identified, among these requests, a user likely linked to the Chinese military. This user was seeking to analyze surveillance footage.
DeepSeek employed a different method: the company relayed requests from its own users to Claude Opus without their knowledge. Consequently, over 12.1 million exchanges were recorded in two weeks, including internal documents and active identifiers.
Zhipu, Xiaomi, SenseTime, MiniMax: The Next on the List
Zhipu, Xiaomi, SenseTime, and MiniMax complete the list of labs flagged by Anthropic. Furthermore, one of them even tested over 12,000 different methods to extract Claude's hidden reasoning, eventually finding some that worked. The complete document details all the indicators of compromise, campaign by campaign.
Anthropic states that it has banned the accounts, shared its indicators of compromise with authorities and the industry, and strengthened its safeguards based on each case. Neither Moscow nor Beijing has confirmed these allegations, which rely solely on Anthropic's data. This is not the first exercise of its kind. We reported back in August 2025 how a lone cybercriminal used Claude Code to extort 17 organizations. A year later, the scale has changed dramatically. States, armies, and multinational AI companies are now in the same column of the table.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Oil Crisis: 5 Reasons Why the Surge Won't Stop

ESMA Warns of Growing Links Between Crypto and Finance

How to Calculate Bitcoin Profit for Beginners Easily - Fintech World
![[Full Text] Solana Foundation: "Korean STOs Should Start Within Regulations and Expand Globally"](/public-static/10_5acc261b9b.png?format=avif)
[Full Text] Solana Foundation: "Korean STOs Should Start Within Regulations and Expand Globally"

Can Bitcoin Be Bought with Rp50,000? Here's How - Fintech World

JPMorgan Bullish on Meta: Muse, Model API, and Subscriptions Support $820 Target Price

Russia to require tax IDs for opening crypto depository accounts

Mr&强 Summarizes the Latest Progress of the TermiX Project

How to Raise iPhone Prices Without Hurting Sales? JPMorgan Analyzes Apple's 'Installment Strategy'

Robinhood is Trading Fruit Flies, Solana is Trading Cats

Wells Fargo CEO Claims the Clarity Act May Harm the Financial System?

What is Fibonacci retracement? Trading Minute

Ukraine has lost half of its warehouses: co-owner of the chain talks about the retail situation and risks of shortages

Bitcoin Adoption Boosts Sales by 19%! Iconic U.S. Restaurant "Steak 'n Shake" Achieves Double-Digit Growth

RWA Perpetual Futures Trading Volume Reaches $120 Billion, Increasing 120 Times in One Year

What AI Trading Needs is a Managed Workflow, Not Just Answers

Teacher's Day: How Much Teachers Earn in Argentina and Which Province Pays the Best

BIT Trust White Paper 2.0 Released... Presenting a Secure, Compliant, and Verifiable Trust System

Kaia Secures Wallet and Payment Network in Japan for Stablecoin Usage

OpenAI Launches Financial Services-Specific ChatGPT, Replacing 100-Hour Wall Street Banker Tasks

Variational Swap Records $2.8 Billion in Trading Volume Within a Week of Launch

Oracle Surpasses Revenue with AI: What Explains the Turnaround

David Schwartz Predicts XRP Could Overtake Bitcoin by Market Cap

US Clarity Bill: Senator Cynthia Lummis Publishes Revised Version Before Vote

Solana Launches Prediction Market Amid Technical Hurdles

Solana Breaks Records, But Its Daily Revenues Make the Difference

Iran Rebuilds Missile Power... "Capable of Producing Hundreds to Thousands" - WSJ

DZI Linked to an Offer of 3.1 Million Identity Records

This Guy Cloned Sam Altman, Elon Musk, and Zuckerberg Into AI Bots. They Immediately Started Fighting










