I just went through Anthropic’s threat report & woah!
This is genuinely the craziest article I’ve read all month.
They documented hackers, governments, scammers and Chinese AI labs all using Claude in completely different ways.
& some of the cases are insane.
Here’s a TLDR;
⟣ A suspected Russian state linked group used Claude across phishing, intrusion, data theft and malware development, including rebuilding malware after security products detected it.
According to the article, more than 20 organizations were targeted.
⟣ ShinyHunters-linked hackers used AI agents to scan 1.8M Android apps for exposed secrets and help run breaches across multiple companies.
Anthropic says the agents did nearly all the work in some operations.
⟣ A China-based group built an automated exploit setup that could research vulnerabilities, build offensive tools and keep working against targets with little to no supervision.
⟣ Claude was also being used for government surveillance.
One consultant used it to build Lakana 360 for Mali’s intelligence service, a system designed to monitor roughly 25M SIM cards across the country, including calls, messages, voice interception, watchlists and automated intelligence dossiers.
The finished system runs locally, so even if anthropic bans the account, it won’t shut it down.
⟣ Anthropic found Claude being used across six weapons programs.
One Yemen-based group used multiple Claude Code instances while working on guided rockets, ballistic missiles and a hypersonic-glide project.
They actually tested one of the rockets, it failed, and they returned to Claude afterwards to diagnose the problem.
⟣ A Russia-based team was working on autonomous FPV kamikaze drones capable of identifying target classes, including humans, and approving lethal engagement without a human making the final call.
⟣ One China-linked project built electronic-warfare and air-defense suppression systems, then later changed its scenario to 12 targets in Taiwan, including radar sites, air bases and command infrastructure.
⟣ Anthropic found multiple influence operations too, including fake news networks, fake political accounts, propaganda operations and systems built to copy the writing style of real people.
⟣ Then there’s this fucking dating operation.
More than 20 dating apps.
> 4,700+ AI personas.
> 25,000+ people talking to them.
> Around 2.36M Claude messages in two weeks.
And when someone wanted a video call or social follow, real gig workers could step in to make the fake profile look legit.
⟣ Then Anthropic gets into distillation.
They say they’ve now caught campaigns from Alibaba, Moonshot, DeepSeek,
Z.AI, Xiaomi, SenseTime and MiniMax.
Alibaba alone allegedly ran 151M+ Claude exchanges between May and July, peaking at almost 3M per day.
(I just wrote a piece on distillation before this)
> Moonshot: 23M+.
> DeepSeek: 12.1M+ in 14 days.
And this is where it gets messy.
Anthropic says Moonshot and DeepSeek were sometimes routing requests from their own users through Claude without telling them.
Those requests included internal company documents, source code, live credentials, surveillance data and other sensitive information.
⟣ Some labs were also actively trying to extract Claude’s hidden reasoning.
Anthropic says one lab tested 12,000+ different requests, each trying a different method, until it found techniques that worked and scaled them up.
That’s the TLDR.
Got me feeling like 👇
We're publishing our most detailed threat intelligence report to date.
It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them.
We disrupted every operation in the report, and used the lessons from them to strengthen our safeguards. Where appropriate, we also shared what we found with authorities and other AI companies.
These cases are not typical: we’re highlighting some of the most sophisticated misuse we’ve seen. But they’re especially important to discuss, because they show us where AI misuse is headed, where our safeguards work, and where they need to improve.
We’re publishing this report so others can spot the same activity on their own platforms, and so we can give the public a clearer view of how emerging threats develop.
Read the report:
anthropic.com/threat-intelli…