Anthropic has published a report claiming that operators from Russia and China have leveraged Claude for cyberattacks, mass surveillance, and weapons development. The document details specific incidents and the model’s role in everything from reconnaissance and phishing to hacking, automated exploit testing, and maintaining attacker infrastructure. You can check out all the details in Anthropic’s new threat intelligence report.

Russian and Chinese Operations

According to the report, one Russian account used Claude at nearly every stage of cyber-espionage—gathering intel, crafting phishing lures, breaching systems, stealing data, and automatically tweaking malware after it was detected by security tools. In China, Claude was tapped for vulnerability research, launching attacks, and running large-scale surveillance. In one case, the model helped build exploits and almost fully automate attack testing. In others, it was used to compile dossiers on dissidents, Uyghurs, and religious groups.

Weapon Projects and Drones

Anthropic says a group in Yemen used multiple Claude AI agents as a “team of engineers” to develop missile guidance software. The devs even ran a live test launch, and after it failed, they went back to Claude to troubleshoot. The report also highlights a Russian developer group working with Claude on an autonomous swarm of kamikaze FPV drones; Anthropic believes these were a small team of freelancers, not a government outfit.

Mass Surveillance and Social Engineering

One developer deployed Claude as the main tech muscle behind a surveillance system targeting all three mobile operators in Mali, covering about 25 million SIM cards. The system could analyze calls, SMS, and voice traffic, track people by voice, and build detailed dossiers. In China, Claude was used to manage a network of over 4,700 fake profiles in dating apps; within two weeks, these bots interacted with at least 25,000 people and sent around 2.36 million messages (per Anthropic’s estimates).

Cybercrime

The report says ShinyHunters hackers used Claude in nearly every phase of their attacks. In one instance, it took just about three hours to go from a stolen token to full control of a cloud infrastructure.