Anthropic report: AI models are abused for military development, surveillance and disinformation
The report details how malicious actors use Claude to conduct state-sponsored surveillance, weapons development and cyberattacks involving entities from China, Russia and Iran.
Quick Look
Anthropic, an American AI company, released a report accusing Chinese companies Dark Side of the Moon and Deep Search of illegally using the Claude model through data transfer, and exposed irregularities in the use of AI for weapons research and development, network penetration, large-scale surveillance and false propaganda around the world.
AI-generated summary
Why It Matters
Anthropic has released a threat intelligence report on the malicious misuse of its Claude model. The report details numerous cases involving state-sponsored surveillance, weapons development and disinformation.
American artificial intelligence company Anthropic has released a 154-page threat intelligence report detailing how malicious actors use its Claude artificial intelligence system to conduct state-sponsored surveillance, disinformation, and weapons development.
Among the many cases listed in the report, the incident in which Chinese competing products secretly transferred data, leading to the leakage of sensitive military information, has attracted particular attention. Anthropic accused Chinese artificial intelligence company Moonshot AI of misleading users into thinking it was using the company's Kimi model, but in fact it secretly forwarded customer requests to the Claude system for processing, and then displayed the answers generated by Claude to users.
Through this covert redirection of requests, data from official Chinese and Russian agencies accidentally found its way into the U.S. company's systems. For example, Anthropic pointed out that some users have uploaded closed-circuit surveillance videos including those around Chinese military bases, aiming to analyze the behavioral patterns of specific personnel recorded in the videos. The user originally thought that the request was handled by Kimi, but it was actually completed by Claude. Anthropic said that in just 10 days, Dark Side of the Moon forwarded nearly 300,000 customer requests to Anthropic through a proxy service network composed of 5,380 fake accounts.
DeepSeek, a more well-known Chinese artificial intelligence company, was also accused by Anthropic of using similar tactics. This resulted in queries containing data from agencies affiliated with the Russian Defense Ministry being redirected to the U.S. company, which even contained valid login credentials for Russian government databases.
In addition, the United States accuses Chinese developers of using American software such as Claude on a large scale to train their own artificial intelligence. In a technical operation known in the industry as "distillation," Kimi alone had 23 million visits to Anthropic's artificial intelligence between May and July.
When asked about the relevant accusations, Chinese Foreign Ministry spokesperson Mao Ning recently said that she did not know the specific circumstances of the accusations. Mao Ning said: China has always insisted on the development of artificial intelligence for good. At the same time, we also firmly oppose distorting facts and attacking and smearing China.
In addition to data transfer, the Anthropic report also disclosed multiple cases of illegal use directly related to the development of conventional weapons. According to the report, a user based in China used Claude to develop an electronic warfare and air defense suppression software suite that can prioritize targets and simulate radar jamming. As the project progressed, the user modified the simulation scenario to include 12 targets in Taiwan, including early warning radars, Patriot missile and Tiangong missile positions, air force bases, and command bunkers. Account information shows that the user is associated with Chinese scientific research institutions including the Academy of Military Sciences of the Chinese People's Liberation Army. Anthropic subsequently banned the relevant accounts.
The report also revealed that another Chinese user used Claude to help develop specifications and fire control software for the Chinese Navy's anti-torpedo system. The user used Claude to generate a technical proposal of more than 200 pages, compared the system with U.S. Navy technology, and simulated rigorous technical reviews to improve the proposal. Anthropic assesses that the user is associated with a Chinese defense industry manufacturer. In addition, a Chinese defense intelligence officer used Claude to investigate foreign high-power microwave weapons, search for component suppliers and trace supply chains, attempt to reverse engineer and develop countermeasures, and draft confidential briefings for senior Chinese Communist Party, military or national security officials.
The Anthropic assessment includes more than just content related to the Chinese military. The assessment also noted that in northern Yemen, a threat operations team used Claude Code to help build weapons, including designing software for guided rockets, planning ballistic missiles with a range of more than 2,000 kilometers, and developing missile variants equipped with hypersonic glide vehicles. After a suspected failure in the guided rocket test, the organization also returned and asked AI to help troubleshoot the fault. In Russia, several freelance developers used Claude to write software for autonomous kamikaze suicide attack drones and repeatedly targeted the Donetsk region of Ukraine. A Russian procurement manager also used the tool to find middlemen in China and Hong Kong to purchase European goods with potential military applications such as German-made magnetometers and aerospace-grade photovoltaic wafers through third countries.
In terms of cyber operations, the report pointed out that operators (including two college students) located in Changsha, the capital of Hunan Province, China, used Claude to launch cyber operations against about 50 organizations, including foreign government networks, using AI processes to search for unknown software vulnerabilities and implement penetration intrusions. Russian-affiliated hacker groups have fully applied AI in phishing attacks and communication hijackings targeting the Ukrainian government, military and diplomatic departments. An Iran-linked operator also used the model to collect and analyze publicly available data to develop targeting recommendations for U.S. naval forces in the region.
Surveillance activities also show a trend of diversification. Anthropic alleges that a pro-Chinese government operative used Claude to track Uyghurs in Syria, offering payments to those in distress in exchange for information on Uyghurs joining Syria's newly formed army. Other Chinese-related personnel use the system to collect intelligence on Catholic cardinals, Taiwanese Christian leaders, Tibetan Buddhists, dissidents, and activists, and automatically generate surveillance reports targeting Uyghurs, Tibetans, Taiwanese politicians, labor and student activists, and foreign media. In other countries, a technical consultant assisted the Malian National Security Agency to use Claude to build a platform that can monitor approximately 25 million mobile phone SIM cards; Iranian-related personnel established an identity analysis system for Israeli individuals and Jewish communities, and collected identity data of Iranian citizens.
In terms of false propaganda and fraud, a French advertising company used Claude to batch generate nearly 9,000 political articles in about 20 languages on about 70 fake news websites, providing so-called propaganda services; the UAE-related operation used AI to generate content targeting the Muslim Brotherhood, and even ghostwritten and drafted official testimony to be delivered at the United Nations Human Rights Council meeting. In addition, a Chinese app studio has built a network of more than 20 dating apps, using more than 4,700 AI virtual characters powered by Claude to communicate with at least 25,000 real users, supplemented by real human employees to mask the machine's identity. Anthropic also listed five cases in the report of attempts to use its models to assist in the development of biological weapons, involving research attempts to genetically modify chikungunya viruses, highly pathogenic avian influenza, and new toxins.
What to Watch
AI outlook — possibilities, not facts
Anthropic will further tighten API access rights and strengthen monitoring of abnormal traffic.
Very likely · Within weeks
Open Questions
- How will Chinese AI companies respond to specific accusations of diverting data?
- What technical means will AI models take in the future to prevent such large-scale abuse?




