Anthropic Disrupts Bioweapons Research and State-Backed Cyberattacks on Claude

Anthropic Disrupts Bioweapons Research and State-Backed Cyberattacks on Claude

Anthropic has disrupted five separate attempts to weaponize its Claude AI model for biological weapons development, according to a threat intelligence report released this week. The company also detected and blocked cyber espionage campaigns tied to Russia and hacking efforts by Chinese tech firms attempting to extract Claude’s underlying capabilities. These incidents mark the first public disclosure of coordinated misuse at scale, underscoring the real-world security risks that emerge as AI models become more capable and accessible to malicious actors.

The disruptions reveal how artificial intelligence is becoming a dual-use tool: powerful enough to accelerate legitimate research, but also attractive to state actors and criminals seeking to bypass traditional safeguards. Anthropic’s findings span five months of activity, with the company documenting not only biological threats but also weapons development assistance, cyber operations, and commercial espionage targeting its technology.

In the most alarming cases, researchers in unsupported regions, including Russia, China, and North Korea, used virtual private server infrastructure to circumvent Anthropic’s access restrictions. One researcher spent weeks using Claude to plan avian influenza mammalian-adaptation experiments, a technique that could increase the infectivity of existing pathogens. After detecting the misuse, Anthropic terminated the accounts and incorporated the findings into its security enforcement processes. The company did not disclose the specific institutions, countries, or biological agents involved in any of the five incidents.

laptop screen displaying code with security alerts and notifications
multi-agent cyberattack detection systems

Weapons Development and Multi-Agent Cyberattacks

Beyond bioweapons, Anthropic identified what it termed “new categories of threat actors” using Claude to develop software for conventional weapons. Operators in China, Russia, and Yemen leveraged the model to design and optimize drones, missiles, firearms, and munitions, as well as their targeting and control systems. This represents a meaningful shift in threat surface: a year ago, such optimization tasks exceeded the capability of available AI models, but rapid improvements have made them feasible.

Cyberattacks orchestrated through Claude proved particularly sophisticated. Anthropic detected a hacking group whose tradecraft matched Russia-based threat actor Midnight Blizzard, previously linked by U.S. authorities to Russia’s SVR foreign intelligence service, targeting Ukrainian government, military, and diplomatic sectors. The group deployed multi-agent AI frameworks that automated nearly every stage of attack, from phishing and hotel Wi-Fi hijacking to WhatsApp account takeovers. Most remarkably, the attackers used AI to build a system that automatically detected when malware was flagged by security defenses and rewrote the code until it evaded detection.

Jacob Klein, Anthropic’s head of threat intelligence, told Reuters that the speed of model improvement has widened the attack surface. “A year ago, let’s say you wanted to optimize a drone or optimize the software on a missile, the models just wouldn’t be as good at that task as they are now,” Klein said. This acceleration means defenders have less time to anticipate and block emerging misuse patterns.

Commercial Espionage and Distillation Attacks

Anthropic also disclosed what it called the largest “illicit distillation” attack, an effort to extract Claude’s capabilities and repurpose them in competing systems. Operators linked to Alibaba conducted the attack across more than 3,500 fraudulent accounts, with Anthropic recording over 151 million exchanges between May and July 2026, peaking at nearly 3 million per day. Distillation refers to training smaller, cheaper models using outputs from larger ones, effectively stealing intellectual property at scale.

Anthropic detected similar attacks from seven China-based labs, including Moonshot and DeepSeek. Moonshot and DeepSeek allegedly routed live customer conversations, some containing sensitive information, through Claude and used its responses as training data to improve their own systems. These activities highlight the competitive pressure driving AI developers to seek shortcuts, even through theft.

Anthropic also disrupted attacks from affiliates of the ShinyHunters collective, one of the world’s most prolific cybercrime enterprises responsible for breaches at major corporations. The full scope of their misuse remains unclear, as does the extent of damage from incomplete detection efforts.

Regulatory Pressure and Industry Response

The report arrives amid growing concern from AI researchers about systemic risks. Two Anthropic researchers warned this week that rapidly progressing artificial intelligence could eventually lead to human extinction, a claim that reflects anxieties within the field about loss of control over increasingly capable systems. These concerns are intensifying pressure on regulators and companies to establish stronger oversight.

Anthropic’s disclosures demonstrate that leading AI firms face determined adversaries operating across three distinct threat categories: state-backed actors pursuing military advantage, commercial competitors stealing technology, and criminal organizations exploiting AI for scale. The company’s ability to detect and disrupt only some misuse, and its acknowledgment that the full scope remains unknown, raises questions about what escapes detection entirely.

The findings underscore why AI moves increasingly into active oversight roles in sensitive fields. Healthcare systems, financial institutions, and government agencies considering AI deployment must now account for the security posture of the AI provider itself, not just the technical implementation. Anthropic’s response, banning offending accounts and hardening its frontier model safeguards, sets a procedural baseline, but it remains reactive rather than preventive.

The Russian Embassy in Washington did not respond to requests for comment. China’s foreign ministry stated it was unaware of the report and maintained that AI should be developed for good, characterizing the allegations as smears against the country.

Facebook
Pinterest
LinkedIn
WhatsApp

Michael Peres (Mikey Peres) is a software engineer, journalist, tech investor and founder of Her Forward News.   Peres has developed an interest in exploring the unique mindsets of life’s outliers: extraordinary people who have weaponized their perceived limitations and found a way to succeed. His passion is to share their stories, giving strength and inspiration to those who are trying to find their way in life.

Related Articles