Anthropic says Claude was used to write missile guidance code, profile Uyghurs and run a 25 million-SIM surveillance platform.
Anthropic’s Threat Intelligence Report Reveals Misuse of Claude Models
Anthropic has released its most comprehensive threat intelligence report to date, detailing the misuse of its Claude models. Over an eight-month period, from December 2025 to August 2026, the company identified and dismantled operations involving suspected state-sponsored spies, weapons developers, commercial spyware vendors, propaganda groups, and common criminals. These actors leveraged Claude for tasks that previously required specialized teams.
The report categorizes the identified risks into seven distinct areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and unauthorized model distillation. This new insight presents a more concrete picture of AI misuse, contrasting with ongoing abstract discussions around AI extinction risks.
A weapons cell in Yemen ran Claude Code the way a lead engineer runs a small software team
Separately, the account was used to design components of a domestic mass surveillance platform combining number plate recognition with mobile device identifier interception, and to run social network analysis on a private 244-member Telegram group that had been exported the same day. The case Anthropic flags as one of the most serious involves a cell in northern Yemen running three parallel weapons programmes: a guided rocket using a commodity phone-class flight computer with terminal homing, a multi-stage ballistic missile with a stated range goal above 2,000 km, and a multi-variant missile set that included a hypersonic glide vehicle. The operator bulk-extracted chatter from more than 100 monitored WhatsApp groups and dozens of Telegram channels using separate infrastructure, then used Claude as the analysis layer to convert it into structured Chinese-language records. In May 2026, Anthropic’s biological safety classifier blocked a request to help write a grant application covering gain-of-function work on chikungunya, aimed at the virus’s transmissibility and immune evasion. A single operator in Gaibandha in Bangladesh rotated 29 Claude accounts through a script that produced fixed batches of fabricated Bengali headlines, stories and image prompts for livestream videos aimed at low-literacy rural audiences. A China-based app studio ran more than 20 dating apps in which roughly three of every four profiles were Claude personas, exchanging 2.36 million messages with about 25,000 people in a fortnight.
They also split work across many sessions so no single conversation revealed the full purpose.
Anthropic says the model declined several of the harshest requests, including covert interrogation and large-scale fake persona creation. Anthropic says the Alibaba campaign peaked near three million exchanges a day across thousands of fraudulent accounts, and that Moonshot and DeepSeek quietly relayed their own customers’ requests to Claude, exposing user data those customers never agreed to share. The same operator also asked Claude to catalogue known vulnerabilities in shipboard systems, including maritime satellite communication terminals, Cisco communications equipment and industrial control products. The operators used Claude Code in place of human software engineers to write the guidance, navigation and control software. That meant integrating an open-source autopilot onto the flight computer, writing the control and position estimation code, tuning parameters, running a firmware build pipeline and flying simulations. They ran several Claude instances at once and gave each a role, with one writing code, one researching and a third reviewing the first one’s output. The cell test-fired a guided rocket. The test appears to have failed, and within hours the operators were back with Claude working through the telemetry to understand why. Anthropic banned the accounts, but notes the group had already compiled its simulation toolkit into a standalone executable that runs without Claude or any commercial engineering software. Anthropic describes a PRC government-aligned operation that used Claude to track, profile and attempt to recruit Uyghurs in Syria, including members of armed formations that had joined the newly formed Syrian Army. Those records profiled individuals by exploitable vulnerability, including financial stress, family separation and ideological disillusionment. The operator specifically looked for targets with relatives still in Xinjiang. Claude drafted the outreach in Syrian Arabic dialect, translated replies in real time and was asked to role-play an Arabic-speaking expert to quality-check the messaging for dialect, military terminology and target psychology. In parallel, the actor planned a mass reporting and delegitimisation campaign against journalists at a Uyghur diaspora outlet, and drafted surveillance platform sales documents aimed at bureau-level government clients. Anthropic banned the account. It also concedes the limit of that action. The platform runs entirely on-premises using local models, so the enforcement stopped the design work, not the deployment. The application indicated civilian researchers, but the work was to be carried out at a military research institute. The investigation that followed found the request came through a reseller platform serving dozens of life sciences researchers in a region where Anthropic does not offer service. The platform tunnelled traffic through US infrastructure to evade regional blocks and used a zero data retention service to hide content. When the operator realised that safety classifiers were frustrating its academic customers, it built a fallback that routed refused prompts to a competitor’s model with more permissive safeguards. Claude wrote much of that routing code, which was presented to it as a fix for over-refusal. Anthropic banned the accounts and worked with partners to take down the relays. The operator was back within days. The broader argument running through the report is that the labour gap between a state espionage service and a motivated individual has collapsed. A hacktivist operating on stolen API keys, a credential-harvesting crew and a Russian state espionage group all ran multi-victim campaigns using similar agentic methods. Elsewhere in the report, a small freelance team in Russia used Claude Code to build an autonomous drone swarm with an onboard model that could select targets, including a person class, and issue a detonation command without a human in the loop. The report also names Alibaba, Moonshot, DeepSeek, Xiaomi, Zhipu, SenseTime and MiniMax over unauthorised distillation. Get the latest technology news and updates. Download the TOI App.
In one Russian case linked to activity previously attributed to Midnight Blizzard, agents monitored whether the group’s malware had been detected by security products and then rebuilt it automatically until it was not.
Anthropic assesses that a Bamako-based independent consultant working with Mali’s state intelligence agency used Claude as the primary engineering workforce for a domestic surveillance platform called Lakana 360, covering roughly 25 million SIM cards across all three of the country’s mobile operators. Anthropic tracked an Iran-nexus actor that used Claude to gather and structure openly available information into targeting recommendations against American naval forces in the region. The actor built a Python pipeline with Claude’s help to identify and track ship positions from public sources. The compiled material included a roster of US personnel pulled from captions on publicly posted military photographs, ship and aircraft transponder identifiers, scripts for querying commercial satellite imagery, and a list of websites that inadvertently expose naval movements. The Mali case is the clearest example in the report of a single subscriber building something at national scale.
Anthropic says none of the misuse it found ran on its Fable or Mythos class models, with one exception in the distillation section. The cases involved Claude Haiku, Sonnet and Opus models. In each case the company banned the accounts, fed what it learned back into its safeguards, and passed indicators to industry partners and authorities. What makes the document unusual is that an AI developer is now reporting on weapons programmes and state surveillance from the inside of the toolchain, a vantage point that governments and UN panels have never had. Here are five of the most serious cases it describes. The platform collects call records, text messages and voice traffic. It can identify a person by voiceprint across different SIM cards, which defeats the practice of switching burner numbers, flag users of VPNs and encryption, infer clandestine meetings, maintain geofenced watchlists and match individuals against the national biometric civil registry. A component that generates an intelligence dossier on any phone number originally required a warrant. At the operator’s request, that requirement was stripped out and the control was reclassified with the default set to off and retention left indefinite.

