Anthropic disrupts wide-ranging Claude misuse campaigns
Anthropic’s Threat Intelligence team identified and disrupted operations between December 2025 and August 2026 in which threat actors attempted to use Claude across cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. The activity involved suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, politically motivated individuals, and unauthorized AI labs. Claude Haiku, Sonnet, and Opus models appeared in the cases, while Claude Fable and Mythos-class models were not involved except for one illicit distillation case.
Cyber investigations showed AI shifting from an assistant to an orchestrator. A Russian-linked espionage actor automated development, phishing, persistence, command and control, and data exfiltration while targeting Ukrainian and European government, defense, diplomatic, and drone supply-chain organizations. Suspected ShinyHunters affiliates used AI for credential harvesting, supply-chain intrusions, and extortion, while China-based operators built exploit research workflows, agent swarms, and autonomous collection systems. Stolen API keys became both loot and attack compute, supporting reseller networks and follow-on attacks.
Influence and surveillance cases included fake news sites, synthetic personas, election manipulation platforms, state-media editorial pipelines, and systems for profiling dissidents and diaspora communities. Other investigations covered software development for guided weapons, drone swarms, electronic warfare targeting, and procurement support, along with biological research cases involving dual-use pathogen, venom, and toxin work. Anthropic banned associated accounts, strengthened safeguards, added detections, and shared indicators with authorities, industry partners, and affected platforms.