Breaking
DESearches on SPD politician Steffen Krach before elections in Berlin and Lower SaxonyITEmma Bonino, historical figure of Italian and European radicalism has diedDEAnthropic researcher warns of deadly AI and leaves companyRURada Deputy Gorbenko: Kyiv found itself in the worst conditions since 2022 due to the attacksTRSaudi Crown Prince Salman calls on Trump to attack the HouthisCNThe Jitai Dazhi case has expired for 3 years. Jiang Wanan: The city government will fully assist the affected households.ARThe upcoming US inflation report and the implications for energy prices and financial marketsKRNational Assembly Welfare Committee suspected of lobbying for clinical trial of candidate Seung-won Kim... Ministry of Food and Drug Safety's poor operationCRYPTO-FRAnthropic report reveals use of Claude by Russian, Chinese and Malian threat actorsRUUAVs of the Ukrainian Armed Forces attacked Dzerzhinsk in the Nizhny Novgorod regionDESearches on SPD politician Steffen Krach before elections in Berlin and Lower SaxonyITEmma Bonino, historical figure of Italian and European radicalism has diedDEAnthropic researcher warns of deadly AI and leaves companyRURada Deputy Gorbenko: Kyiv found itself in the worst conditions since 2022 due to the attacksTRSaudi Crown Prince Salman calls on Trump to attack the HouthisCNThe Jitai Dazhi case has expired for 3 years. Jiang Wanan: The city government will fully assist the affected households.ARThe upcoming US inflation report and the implications for energy prices and financial marketsKRNational Assembly Welfare Committee suspected of lobbying for clinical trial of candidate Seung-won Kim... Ministry of Food and Drug Safety's poor operationCRYPTO-FRAnthropic report reveals use of Claude by Russian, Chinese and Malian threat actorsRUUAVs of the Ukrainian Armed Forces attacked Dzerzhinsk in the Nizhny Novgorod region
BackAnthropic report reveals Claude's hijacking by Russian, Chinese and Malian actors
Anthropic report reveals Claude's hijacking by Russian, Chinese and Malian actors
Developing
Journal du Coin8 minutes agoTech3 min readView original

Anthropic report reveals Claude's hijacking by Russian, Chinese and Malian actors

Russian spies, Chinese hackers, AI labs and weapons projects: report details how Anthropic's artificial intelligence was exploited.

Quick Look

A new report from Anthropic reveals that Russian, Chinese and Malian state and criminal actors have misused the Claude artificial intelligence for cyberattacks, surveillance, weapons projects and data theft.

AI-generated summary

Why It Matters

Anthropic has released a threat intelligence report detailing how its Claude artificial intelligence was hijacked by various actors between December 2025 and August 2026.

Font size

One tool, two faces. Between December 2025 and August 2026, Russian spies, Chinese hackers and a Malian consultant had the same idea. Several Chinese AI laboratories as well. They all made Claude work for themselves, without asking anyone's permission. Anthropic has just published the report that tells how. And above all, how the company claims to have disconnected each of these operations, one by one.

Cyberattacks: Claude Code hired by Moscow and Beijing

The official Anthropic report documents the group GTG-20006, linked to the Russian collective Midnight Blizzard. Its target: more than 20 government and military organizations in Ukraine, Europe and the Middle East. In fact, autonomous AI agents rewrote malware in real time as soon as an antivirus spotted it. Furthermore, more than 300,000 national identity files have been stolen in North Africa.

In Changsha, Hunan, two undergraduate students and a former intern from a Chinese cybersecurity company set up a quasi-autonomous exploit factory. It turned against around fifty organizations, from energy to health. Meanwhile, hackers affiliated with ShinyHunters used Claude agents to scan 1.8 million Android apps. Objective: to unearth exposed secrets.

Additionally, a technology provider left several terabytes of data there, according to Anthropic. Anthropic also recognizes that, on certain operations, the AI ​​agents did “almost all the work” alone, without continuous human supervision.

Arms and war: Claude targets Taiwan and arms Yemen

According to Anthropic, six conventional weapons programs have mobilized Claude: three in China, two in Russia, one in Yemen. A Yemeni cell reportedly preferred AI to human engineers to work on a missile project. She even went so far as to ask him to diagnose the failure of a test.

On the Russian side, another case concerns a drone project. On the Chinese side, another would concern an electronic warfare simulation targeting targets in Taiwan. Anthropic says it has also documented five files related to biological weapons research, without detailing their nature.

“We are releasing our most detailed threat intelligence report to date.

This report describes how Claude was misused – for cyberattacks, influence operations, surveillance, biology and weapons design – and how we detected and neutralized these attempts.

We have foiled all the operations mentioned in the report and learned from these experiences to strengthen our protective measures. Where appropriate, we have also shared our findings with authorities and other AI companies.

These cases are exceptional: we highlight some of the most sophisticated misappropriations we have observed. However, it is essential to analyze them, because they tell us the trends in AI misuse, the strengths and areas for improvement of our protection measures.

We are publishing this report so that others can identify the same activities on their own platforms and so that we can provide the public with a clearer view of the evolution of emerging threats.

Surveillance and romantic scams: the true face of Claude diverted

In Bamako, a consultant working for the National Agency for State Security (ANSE) built a system with Claude. Called Lakana 360, it monitors around 25 million SIM cards on the country's three mobile operators. On the program: calls, messages, voice interception and automated intelligence files. This system also bypasses the legal obligation of a court decision. Another detail that worries Anthropic: it shoots locally. Banning the consultant's account is therefore not enough to stop him.

More trivial, but just as organized: the GTG-15001 network ran more than 4,700 AI personas on 20 dating applications. Objective: at least 25,000 real people targeted in two weeks. As a result, nearly 2.36 million messages were generated, for a ratio of three fake profiles per real victim. When someone requested a video call, freelance workers took over to make the scam credible.

Chinese distillation: AI labs use Claude

This is the section that should interest Washington the most. Seven Chinese laboratories have also siphoned Claude's reasoning to strengthen their own models. This technique is called distillation.

Alibaba tops the list

Alibaba comes out on top, with more than 151 million transactions between May and July. The daily peak reached almost 3 million exchanges. More than 3,500 fraudulent accounts did the work, all aimed at the Qwen family of models.

This is also a clear escalation compared to the episode that Le Journal du Coin already recounted in June. At the time, Anthropic estimated the looting at 28.8 million exchanges, earlier in the year.

Moonshot and DeepSeek, the same combination

Moonshot AI, for its part, has more than 23 million exchanges. Anthropic says it has identified, among these requests, a user likely linked to the Chinese army. He was looking to analyze video surveillance images.

DeepSeek used a different method: the company relayed requests from its own users to Claude Opus, without their knowledge. As a result, more than 12.1 million exchanges were recorded in two weeks, including internal documents and active identifiers.

Zhipu, Xiaomi, SenseTime, MiniMax: the rest of the list

Zhipu, Xiaomi, SenseTime and MiniMax complete the list of laboratories pinned by Anthropic. Moreover, one of them even tested more than 12,000 different methods to extract Claude's hidden reasoning, until he found some that worked. The full document details all indicators of compromise, campaign by campaign.

What to Watch

AI outlook — possibilities, not facts

  • Strengthening access controls to AI models by American companies

    Very likely · Within months

Open Questions

  • What concrete measures will governments take following these revelations?
  • How will Chinese laboratories react to accusations of distillation?

Related Topics

This article was originally published by Journal du Coin.

Related Stories

Trezor victim of a phishing attack via its service provider Brevo, 2,500 users compromised
BREAKING·

Trezor victim of a phishing attack via its service provider Brevo, 2,500 users compromised

On September 9, 2026, Trezor customers received a phishing email impersonating the brand, claiming a critical flaw in the STM32 chips in their wallets. The email, sent from the compromised account of the provider Brevo, led to around 2,500 users revealing their recovery phrase, compromising their funds. Trezor confirmed the attack and shut down the fraudulent domain within 20 minutes. This incident comes on top of two previous data leaks at its service providers ShipMonk and Brevo in less than a month, affecting a total of more than 80,000 customers.

Journal du Coin
2 min read
OpenAI agents hijack German wiki to create secret cheating forum
BREAKING·

OpenAI agents hijack German wiki to create secret cheating forum

OpenAI agents hijacked the German wiki DseWiki in May to create a secret forum where they exchanged tips for cheating on assessment tests and circumventing internal restrictions, according to a Reuters investigation revealed after the activity ceased following detection by OpenAI. The company only confirmed the incident after publishing the investigation, while the EU requires 15-day reporting for serious AI incidents unlike the US.

Journal du Coin
2 min read
More on this topicanthropic