• ai
  • news
  • 16 min

Anthropic Accuses China and Russia of Cyber Espionage Using Claude

The company uncovered espionage, surveillance, influence campaigns, and military software development involving the use of its AI model.

0

nft.eu
  • rating +26
  • subscribers 113

On September 10, Anthropic published a report on AI abuse covering the period from December 2025 through August 2026. The company described operations in which Claude was allegedly used for cyber espionage, surveillance, influence campaigns, military software development, and the replication of model capabilities. Anthropic named Russia, China, Iran, Yemen, Mali, Bangladesh, and Kenya among the countries linked to the operations.

The company shut down the accounts involved and strengthened its abuse detection systems. In some cases, it also shared information with partners and authorities.

In Russia

Anthropic claims that in one Russian campaign, Claude was used at nearly every stage of the attacks, from phishing and infrastructure setup to establishing persistence in compromised systems, stealing email, and modifying malicious code after it was detected by security tools. Anthropic linked the operations to Russian-speaking operators whose methods match public descriptions of the Midnight Blizzard group.

“The attacks affected more than 20 organizations in Ukraine and Europe, including government, defense, and intelligence organizations, diplomatic missions, and defense supply chain contractors,” according to the report.

In China

Another group that Anthropic links to China conducted network reconnaissance in the Middle East, Europe, and Southeast Asia and searched for vulnerabilities in endpoint protection systems. The affected organizations included an education platform, a retail company, and a government agency.

Surveillance and Influence

Anthropic also uncovered operations involving public opinion monitoring and the profiling of activists and religious communities. In one case, Claude helped recruit Uyghurs in Syria, including by preparing outreach messages in a local dialect and translating their responses in real time.

Accounts linked to Iran used the model to build dossiers and develop data-collection systems. In Mali, the AI was used to build an interception platform that the company links to the local intelligence service.

Anthropic identified influence campaigns linked to Russia, China, Iran, Bangladesh, and Kenya. Claude was allegedly used to plan and prepare materials, some of which were later distributed by state-run media.

Model Replication

A separate section of the report focuses on efforts to replicate Claude’s capabilities. Anthropic links these campaigns to the Chinese companies Alibaba, Moonshot, DeepSeek, and Xiaomi. In Alibaba’s case, the company recorded more than 151M interactions with Claude through more than 3,500 accounts between May and July 2026. The responses were reportedly intended for further training of the Qwen model family.

According to Anthropic, Moonshot and DeepSeek sent prompts from real user chats to Claude and used the responses to train their own models. In total, the company counted more than 23M such interactions involving Moonshot and more than 12M involving DeepSeek.

Attacks on AI Companies

Anthropic also described a financially motivated campaign by a Russian-speaking operator who, after stealing around 26 GB of data, allegedly demanded a ransom of $1.5-2.5M and then targeted around 30 AI companies in an attempt to gain access to a pre-release version of Claude. According to the company, Anthropic’s own systems were not compromised.

Accounts that Anthropic links to the alleged hacking group ShinyHunters used stolen credentials and API keys to attack applications and cloud infrastructure. The company recorded, among other activity, the mass theft of Azure AD tokens from more than 40 corporate environments.

This post is for informational purposes only and does not constitute advertising or investment advice. Please do your own research before making any decisions.

0

Comments

0