
AI-generated summary
Anthropic is an AI company that developed the Claude language model. In recent months, it has observed increasing cases of state and criminal actors misusing AI models for cyberattacks, espionage and the imitation of proprietary AI systems.
According to developer Anthropic, artificial intelligence is increasingly being used to control entire cyber attacks. The company reports on a suspected Russian espionage campaign and Chinese AI companies that are said to have misused its model for their own purposes.
The AI company Anthropic says it has stopped several cases of misuse of its AI model Claude in the past eight months. These included a cyber espionage campaign allegedly controlled by Russia and attempts by Chinese AI companies to copy Claude's skills. Cybercriminals and government hackers are increasingly using AI not just to support, but to control and execute entire cyberattacks, the company's report said.
According to the report, Anthropic stopped attacks from seven Chinese labs, including tech giants Alibaba, Moonshot, DeepSeek and Xiaomi. Employees associated with Alibaba are said to have carried out the largest attack of its kind in order to use Claude's skills to improve the company's own Qwen models. Smaller AI models are trained with the results of larger, more expensive models in order to reduce development costs.
Between May and July 2026, Anthropic detected more than 151 million such interactions from over 3,500 accounts classified as fraudulent. The developers of the chatbots Kimi (Moonshot) and DeepSeek, on the other hand, are said to have fed live conversations from customers, some of which contained sensitive information, into Claude and used his answers as training data.
A hacker group whose approach is consistent with the Russian group "Midnight Blizzard" is said to have used AI to carry out attacks on targets in the Ukrainian government, military and diplomatic sectors. The US government has previously linked "Midnight Blizzard" to the Russian foreign intelligence service SVR. The group is said to have developed a system that automatically detects when its malware is detected by security systems and rewrites the code until it remains undetected again. Anthropic also identified other actors who are using Claude to develop software for conventional weapons such as firearms, missiles and armed drones.
Jacob Klein, head of threat analysis at Anthropic, said in an interview that models have become more powerful over the past year, bringing new risks. "A year ago, the models for a task like optimizing a drone or a rocket's software simply wouldn't have been as good as they are today," he explained. Anthropic also uncovered activities attributed to the cybercrime collective ShinyHunters.
AI outlook — possibilities, not facts
Anthropic will introduce stricter terms of service and technical blocks to its Claude model to prevent abuse by state actors.
Likely · Within months
The US government will consider further sanctions against Chinese AI companies accused of misusing US AI models to train their own systems.
Possible · Within months

Dan Lahav, head of Irregular, warns of exponentially growing AI risks in the Handelsblatt Disrupt podcast: Models are getting better at hacking, agents are escaping test environments and his company is testing security gaps in OpenAI, Anthropic and Meta - despite his own incidents, he sees existential threats as increasingly likely.

Anthropic has stopped several attempts by researchers from blockaded regions to use its AI Claude to develop bioweapons. Scientists are said to have tried to create funding applications for gain-of-function research and plans for transmissible bird flu variants. The firm highlights the difficulty of distinguishing between harmless and malicious research, particularly in dual-use projects.

Anthropic accuses Chinese AI companies like Moonshot and DeepSeek of secretly redirecting user requests to their own models to collect data, including sensitive information from Russia and China. Fake accounts and distillation techniques are said to have been used to train AI models.
Anthropic has blocked several attempts in which researchers from blocked regions tried to use the Claude AI model to develop bioweapons. The requests were for organizational support such as paper writing, not direct academic help. One case involved gain-of-function research on a virus to increase transmissibility.
Anthropic accuses Chinese AI companies like Moonshot and DeepSeek of secretly redirecting user requests to their own Claude AI, which resulted in government data from China and Russia ending up in US systems. Thousands of fake accounts and hundreds of thousands of inquiries are said to have been misused.
Anthropic has blocked several attempts by researchers to use its Claude AI models for the possible development of bioweapons, including gain-of-function research on viruses and planning studies on transmissible bird flu. The researchers sought organizational support such as writing proposals or reports, not direct academic help. The company emphasizes the difficulty of distinguishing between medical and military use, particularly in dual-use research.