Anthropic report: Claude misused for weapons software, cyber operations, and disinformation

Anthropic has announced that between December 2025 and August 2026, Claude models were used in weapons software, cyberattacks, surveillance, and fraud.

12punto

Artificial intelligence company Anthropic has reported that its Claude models have been misused by various actors in fields ranging from conventional weapons development processes to cyber operations, surveillance, and fraud.

The report, published by the company to detect and prevent the misuse of its models, covers the period from December 2025 to August 2026. The report states that groups suspected of being state-sponsored, criminal actors seeking financial gain, and institutions linked to propaganda activities have utilized models such as Claude Haiku, Sonnet, and Opus.

Anthropic announced that in the identified instances, accounts were closed, and in some cases, the information obtained was shared with public institutions and private sector organizations.

WEAPONS SOFTWARE AND CYBER OPERATIONS

One of the most notable sections of the report concerns findings that Claude was used in software development processes linked to conventional weapons. According to Anthropic, attempts were identified involving targeting and control software that operates firearms, missiles, armed unmanned aerial vehicles, bombs, and other munitions.

The company's threat intelligence team investigated numerous actors who used Claude last year to produce software for weapons design and development, or to support intelligence gathering and procurement activities that lay the groundwork for weapons programs. The report noted that three of these were located in China, two in Russia, and one in Yemen.

The report stated that Claude models were mentioned in various examples of misuse.

Anthropic reported that it identified a group operating in northern Yemen using Claude Code in three different weapons development programs involving guided rockets and various missiles. According to the report, the group utilized the model for vehicle guidance, navigation and stabilization software, as well as simulation and testing processes. However, the company emphasized that it found no evidence that the group successfully developed an operational weapon.

In another case, it was reported that a China-based actor used Claude for the purpose of developing an anti-torpedo weapon system. It was stated that the actor utilized the model to develop parts of fire control software, prepare test plans, and compare the system with US anti-torpedo and submarine defense programs. Anthropic assessed that the activity was linked to a manufacturer in the Chinese defense industry.

The report also included examples regarding cyber operations. It was stated that Russia-linked espionage activities primarily targeted military intelligence in Ukrainian and European governments. Actors believed to be living in China were noted to have conducted attempts to infiltrate production systems and reconnaissance activities targeting foreign government networks in the Middle East, Europe, and Southeast Asia.

SURVEILLANCE, FRAUD, AND MODEL COPYING ALLEGATIONS

Surveillance activities were also examined under a separate heading in Anthropic's report. It was stated that an account targeting Iran and the Persian Gulf region in June 2026 had set up a surveillance platform to analyze, classify, and profile the social media activities of users in the region. It was announced that the account in question had been banned.

Anthropic reported that accounts involved in misuse attempts were closed and some information was shared with relevant parties.

The company stated that the investigation revealed the account was operated by or on behalf of an organization called “S2T Unlocking Cyberspace.” Open-source research indicated that the organization is an intelligence provider of Israeli-Singaporean origin.

In another surveillance example based in China, it was stated that Claude was used as an automated “public opinion monitoring” tool. According to the report, the user utilized the model to prepare government briefings that classified dissidents, activists, ethnic minorities, the Chinese diaspora, and foreign media as threats to political stability.

Under the heading of fraud, it was reported that a China-based app studio established a network of more than 20 dating apps with the help of Claude. The report stated that AI characters were developed to chat with users, despite claims that the services were provided entirely by humans. It was noted that more than 4,700 AI characters were detected, which had chatted with at least 25,000 people over a two-week period.

The report also addressed attempts to copy artificial intelligence models without authorization.

The report also included examples of the “distillation” method, which refers to training a lower-capacity model by utilizing the outputs of more advanced AI models. Anthropic stated that the method is a common training technique in the field of AI, but becomes illegal when it aims to copy other models without authorization.

The company argued that actors linked to Alibaba attempted to copy the capabilities of the models through illegal means, and that this activity was the largest “illegal distillation attack” recorded to date. The report alleged that approximately 3 million transactions were made daily from over 3,500 fake accounts.

Anthropic also shared examples regarding Moonshot AI, DeepSeek, and Xiaomi. While it was stated that Moonshot forwarded some user requests to Claude instead of its own model, Kimi, the report included the statement, “Users thought they were using the Kimi model, but they were actually receiving responses from Claude.” It was alleged that DeepSeek similarly redirected communications to Claude without informing its customers, and that Xiaomi transferred user chats from its MiMo models to Claude.

In the influence operations section, attention was drawn to networks producing deceptive content through fake social media profiles and news sites. Anthropic announced that a Russia-linked information manipulation operation in the Central African Republic and a commercial disinformation network run by a France-based digital advertising company had been detected and removed.