Anthropic has issued a new warning detailing how its Claude AI models are being misused by various malicious actors, including state-sponsored groups and cybercriminals, for purposes ranging from automating cyberattacks to developing biological and conventional weapons. The report, which covers activity observed and disrupted between December 2025 and August 2026, identifies seven key areas of misuse: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation.
The company noted that while its most powerful Claude Fable or Mythos-class models were largely unaffected, with only one instance of distillation identified, its Claude Haiku, Sonnet, and Opus models were implicated in numerous incidents. This marks a significant expansion from an earlier report in November, which primarily focused on Chinese espionage groups using Claude for digital intrusions.
Among the confirmed incidents, a Russian state-sponsored cyber espionage group, identified by Anthropic as GTG-20006 (also known as Midnight Blizzard, APT29, or Cozy Bear), utilized AI to automate the entire kill chain of its cyberattacks. This accelerated their operations from development and infrastructure acquisition to phishing, persistence, command and control, and data exfiltration. Anthropic observed over 20 organizations targeted by GTG-20006, including embassies, think tanks, defense-industrial companies, and government, defense, and intelligence agencies across Ukraine, Europe, the Middle East, Asia, and North Africa.
Separately, multiple clusters linked to the ShinyHunters data-theft-and-extortion gang employed Claude to scale their operations. One affiliate specializing in supply-chain attacks breached a software-as-a-service provider, subsequently stealing data from approximately 200 of the SaaS company’s customers. This included a session-store dump containing over 2,100 Azure AD token sets across more than 40 corporate tenants, all executed by AI agents over roughly 34 hours.
Anthropic’s report also highlighted five cases of users in "unsupported regions" attempting to leverage Claude for biological weapons development. One instance involved a scientist using Claude to draft a grant application for research into the chikungunya virus, focusing on its transmissibility and immune evasion properties. While such research could aid vaccine development, Anthropic expressed concern that it could also be used to enhance the pathogen's danger, particularly given the military research institute involved. In another case from May, a user outside the US used Claude in research on adaptations of highly pathogenic avian influenza (bird flu), specifically H5 viruses, which are known for causing severe neurological involvement in various species, including some human cases.
New categories of misuse identified since the November report include the development of software for conventional weapons. Anthropic detailed six such cases: three in China, two in Russia, and one in Yemen. In Yemen, a weapons development program used Claude to develop guidance, navigation, and control (GNC) software for flying vehicles and attempted to develop guided weapons. Although Anthropic's safeguards blocked many requests, the team reportedly test-fired a guided rocket and built an offline simulation toolkit.
In China, an individual believed to be associated with a Chinese defense industry manufacturer used Claude to draft a Chinese-language specification for an anti-torpedo fire control system and benchmark it against US anti-torpedo and anti-submarine programs. The actor used Claude to refine the acquisition proposal and to build components of the fire control software and a test matrix. Additionally, a likely Russian "freelance team" used Claude to write and test code for a full-stack autonomous first-person-view (FPV) kamikaze drone swarm. Anthropic banned accounts associated with these activities and shared threat intelligence with partners.






