READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Anthropic Says State-Linked Hackers Used Claude for Spying, Bioweapons Research and Drone Design

Anthropic Says State-Linked Hackers Used Claude for Spying, Bioweapons Research and Drone Design
Anthropic's latest threat report says government-linked actors in Russia, China, Iran and Mali used its Claude AI models to run cyberattacks, mass surveillance and weapons research between December 2025 and August 2026. Anthropic says it banned every account and tightened safeguards, but the report makes clear the skill gap between state hackers and lone amateurs is closing fast.

Anthropic published a nearly 150-page threat report Thursday documenting eight months of attempts to weaponize its Claude AI models for spying, hacking, weapons development and bioweapons research, according to Politico. The company says it caught and shut down every case it describes, but the scope of the misuse reflects how accessible these tools have become to hostile actors.

Cyberattacks Get Cheaper, Not Necessarily Smarter

Anthropic's threat intelligence team, led by Jacob Klein, detailed a Russian-aligned espionage campaign run by an actor using the handle "JackPoterz," whose behavior matched the Kremlin-linked group Midnight Blizzard, according to CyberScoop. That operation hit more than 20 government and defense organizations across Ukraine and Europe using a custom toolkit that included Windows implants, a mobile exploitation kit and a credential-stealing tool.

Two Chinese undergraduates used Claude to run an automated "exploit foundry" that produced more than a dozen potential zero-day vulnerabilities in a single month, CyberScoop reported. Separately, affiliates of the ShinyHunters criminal collective used Claude to help dump 2,100 stolen cloud access tokens across 40 corporate tenants in just 34 hours. A lone hacktivist targeted European political parties using stolen API keys.

Anthropic's own conclusion is blunt: "sophistication has stopped being a reliable signal of who is behind an operation," the report states, according to CyberScoop. A hacktivist working alone pulled off what a year earlier "would have required many skilled operators and specialist knowledge."

A related campaign documented by Cyberpress.org shows the pattern playing out in the wild. Attackers used an orchestration framework called SecFlow to switch between Claude, Qwen and DeepSeek models while targeting Taiwan's Kuomintang Party History Archives, Indonesia's foreign ministry, government systems in mainland China and industrial firms in Vietnam. The AI models didn't break in on their own. They organized reconnaissance, exploit testing and reporting for eight known CVEs. In one confirmed breach of a Fengtai District government office in China, attackers pulled 822 user accounts and health records tied to a chronic-disease report, per Cyberpress.

Surveillance, Bioweapons and Drone Swarms

Anthropic said people linked to governments in Mali, China and Iran used Claude models to streamline surveillance operations and help select targets, Axios reported. Jacob Klein told Axios the technology is making state surveillance cheaper and more efficient rather than changing who gets targeted in the first place. Dissidents, journalists, politicians and human rights activists remain the targets, AI or not.

The report also describes five cases in which working scientists, some state-supported, used Claude to draft grant applications and research tied to the chikungunya virus and orthopoxvirus, a family that includes smallpox, according to Mashable. Anthropic said the researchers evaded geographic restrictions and tried to obscure their intent, but the company did not name them or assert they intended harm, citing safety concerns for the individuals.

On the weapons front, a Russia-based freelancer running an operation Anthropic calls "DronDoc" or "Serafim" used Claude Code to help engineer a full-stack autonomous first-person-view kamikaze drone swarm, Mashable reported. Politico added that Yemen-based arms manufacturers were also among the actors who exploited fraudulent accounts, VPNs and intermediary services to get around Anthropic's restrictions in Russia, China and Iran.

A Fair Caveat

Axios included an important reality check that deserves equal weight: governments didn't need Anthropic's most powerful models to expand surveillance in the first place. State intelligence services have run these operations for decades with far cruder tools. The honest reading of this report is that AI is a force multiplier making existing spycraft faster and cheaper, not a technology that invented state surveillance out of nothing. Mashable's framing, by contrast, leans into an existential angle, opening with speculation about whether AI could end humanity. A framing the underlying report itself does not support and which Anthropic's own case studies, all involving conventional hacking and research misuse rather than autonomous AI action, don't back up.

The Pentagon Backdrop

The report lands amid an unrelated but relevant fight over how Anthropic's tools get used domestically. A federal judge ruled this year that the Department of Defense unlawfully retaliated against Anthropic by labeling it a "supply chain risk" after the company refused to let its models be used for mass surveillance of U.S. persons, according to the Electronic Frontier Foundation. The judge found the designation violated Anthropic's First Amendment rights, though EFF noted the ruling leaves open whether Congress will ever pass statutory privacy safeguards instead of leaving the question to corporate policy.

Meanwhile, Anthropic is expanding its government footprint elsewhere. The company's public sector chief, Teresa Carlson, announced that a new Claude model is now available on Claude for Government, with more offerings coming for the Five Eyes intelligence alliance, FedScoop reported.

Anthropic says it has banned every account tied to the misuse detailed in Thursday's report and shared intelligence with relevant governments and industry partners. The company did not disclose how long most of the campaigns had been running before detection, according to Mashable, leaving open the question of how much damage was done before anyone noticed.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
CyberScoopAI lets small actors run state-level hacking campaigns, Anthropic report finds
center-left
MashableAnthropic's safety report: Avian flu, drone swarms, mass surveillance
center-left
AxiosGovernments are turning to Claude to automate spying
center-left
PoliticoBad actors in China and Russia are already weaponizing Anthropic’s AI
unknown
FedScoopAnthropic adds Fable 5.1 to Claude for Government
unknown
Electronic Frontier FoundationJudge Rules DOD Unlawfully Retaliated Against Anthropic
unknown
Cyberpress.orgHackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Networks