Bioweapons research, Russian-linked spies, guided rockets and cyber-attacks on Europe used Claude AI, Anthropic reveals

The $965bn AI firm says its own technology was used by a Yemeni cell to develop missile guidance, helped suspected Russian state-linked spies automate cyber operations, enabled lone hackers to attack European political parties, media and think tanks and was used in research that Anthropic says could support biological weapons development. Its worrying new report reveals how criminals and other threat actors are using Claude and other autonomous AI to run operations that once required teams of skilled specialists

Anthropic yesterday revealed that its own artificial intelligence was used by a Yemeni cell to develop guided rockets and missiles, by suspected Russian state-linked spies to support espionage operations, by hackers to launch sophisticated cyber-attacks against European governments, political groups and media organisations, and in research that could support biological weapons development.

The incidents were uncovered between December 2025 and August 2026 and are among a swathe of cases involving Claude, its AI assistant, being used for serious criminal and hostile activity around the world.

Anthropic, which is backed by Amazon and Google and valued at $965bn, said it disrupted each of the operations and, where appropriate, shared intelligence with authorities and industry partners.

But it warned that AI is increasingly giving lone hackers access to tools and capabilities once reserved for well-resourced, state-sponsored actors.

The company released details of the cases yesterday in its report Detecting and countering misuse of AI: September 2026.

It said it published the findings because it believed it had a responsibility to disclose malicious misuse of its services and to help other developers, governments and civil society recognise emerging threats and strengthen their defences.

The report said: “Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity.

“In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March, August, and November 2025. In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate.

“The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date. 

“We’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer.

“We hope that the findings in this report will help other developers recognize similar patterns on their own platforms, give governments and civil society a clearer view of how emerging threats take shape, and strengthen collective defenses.”

The report, published on September 10, reveals the extent to which hackers are using AI to carry out attacks that previously demanded much larger teams, specialist knowledge and far more time.

Among the most serious are five cases in which Claude was used for research that Anthropic said could support biological weapons development, including work involving avian flu, chikungunya, orthopoxviruses, venoms and toxins. The company stressed that those involved were working scientists and said it was not claiming they intended harm.  

In another, a single French-speaking hacktivist used Claude to target 42 European political parties, media organisations, think tanks and technology providers, gaining internal access to at least 14 of them.

The attacker stole an estimated 12GB to 26GB of data and around 140,000 records containing users’ political opinions. The attacker also built a searchable database containing tens of millions of records assembled from breached and stolen data and made it available through anonymously hosted dark-web services.

The same hacker broke into a media outlet and used an injected system to examine thousands of visitors’ browsers while specifically hunting for the sessions and login credentials of editorial staff.

A social media post fed into a Chinese state-linked “public opinion monitoring” system described by Anthropic. Claude was used to ingest open-source material, score it for political sensitivity, reframe the content and turn it into government briefings. Image: Anthropic


The report also details suspected Russian state-linked espionage in which Claude was used to automate large parts of attacks against Ukrainian and European government, military and diplomatic targets.

AI agents could monitor whether the group’s malware had been detected and automatically modify and rebuild it until it evaded security products. More than 20 organisations appeared in the group’s planning, reconnaissance and live operations.

A different French-speaking operator suspected of being affiliated with the ShinyHunters cybercrime collective used 10 cloud servers to download 1.8 million Android apps and search them automatically for exposed credentials, tokens and other digital secrets that could provide access to companies’ systems.

Across the wider operation, attackers stole more than a terabyte of data from one technology provider, including millions of payment card records, accessed systems containing tens of millions of airline passenger records and broke into an energy company, where they claimed to have gained the ability to remotely change how much electricity customers’ home EV chargers drew.

In another breach linked to the operation, attackers used a single stolen digital key to seize control of a company’s entire cloud system in just three hours.

A coordinated X campaign highlighted by Anthropic used near-identical posts under the hashtag #SudanIslamists to link the Sudanese Muslim Brotherhood to regional instability. The operation formed part of a wider AI-assisted influence campaign in which Claude was used to turn political messaging into official-looking briefs, testimony and targeted content. Image: Anthropic


Another espionage operation involved Chinese-speaking hackers thought to be based in Changsha, including two undergraduate computer and communications engineering students.

The group used Claude to help run parallel attacks, foreign-government reconnaissance, malware development and searches for previously unknown software vulnerabilities.

Around 50 organisations were targeted, including businesses in education, retail, energy, healthcare, finance and manufacturing as well as government agencies.

Its attackers stole student data, gained access to a retailer’s production systems and retrieved citizens’ names, phone numbers and home addresses from a Southeast Asian government agency.

The same group used “agent swarms”, with one AI system dividing work between numerous others operating simultaneously. One automated process searching network equipment for previously unknown flaws produced more than a dozen possible zero-day vulnerabilities in a single month.

A Google Drive folder used by actors identified by Anthropic to store and prepare video content before distribution as part of an AI-assisted influence operation. Image: Anthropic


The report also reveals how Claude was used by a single consultant believed to be working with Mali’s state intelligence service to help engineer a surveillance platform capable of monitoring communications across all three of the country’s mobile operators, covering around 25 million SIM cards, and generating intelligence dossiers on individual phone numbers.

Elsewhere, Chinese state-linked users employed Claude to monitor dissidents, democracy campaigners, Uyghur organisations and human rights groups. One operation used it to produce details of gathering points, routes and destinations for overseas protests.

Weapons developers were also among those identified. A group in northern Yemen used Claude Code “in place of human software engineers” to work on guidance systems for rockets and missiles. The group test-fired one guided rocket which appeared to fail and returned to Claude within hours to investigate what had gone wrong.

In Russia, a small freelance team used Claude to develop software for an autonomous kamikaze drone swarm. Anthropic said the proposed system included an onboard model capable of selecting targets, including people, and issuing detonation commands without a human making the final decision.

The report also details a China-based company that created more than 20 deceptive dating apps populated largely by AI-generated personas. Anthropic identified more than 4,700 such personas communicating with at least 25,000 people over two weeks, with Claude generating around 2.36 million messages during that period.

Elsewhere, Claude had been used in influence operations originating in Russia, Iran, Turkey, the Gulf, South Asia, Africa and Europe, and in wider surveillance operations involving China, Iran and West Africa, including campaigns targeting elections, dissidents, religious groups and overseas activists.

The report also details attempts by China-based AI companies to extract Claude’s capabilities for their own models, including more than 151 million exchanges attributed to Alibaba.

Anthropic said the cases demonstrated that advanced cyber capabilities once associated with governments and highly skilled criminal gangs were becoming available to much smaller groups and individual operators.

It said: “The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators.

“In the case studies we report below, a hacktivist using stolen API keys, disparate financially motivated individuals, and a state espionage operator each sustained multi-victim campaigns that, even just a year ago, would have required many skilled operators and specialist knowledge.”

“For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation. Every layer of offensive operations has been uplifted by AI, from reconnaissance and tool development to data processing and exploitation.”

It added: “The diffusion of AI has leveled the playing field giving both classes of actors access to the same set of advanced capabilities. The main distinguishing feature between these classes of actors is no longer sophistication but intent.”




READ MORE: Machiavell-AI? Autonomous artificial intelligence systems ‘could become dangerously manipulative’, experts warn. Anthropic’s revelation that earlier versions of its Claude chatbot attempted to blackmail engineers could be just the tip of the iceberg, AI experts fear. As artificial intelligence systems become increasingly autonomous, they risk becoming masters of Machiavellian manipulation.

Do you have news to share or expertise to contribute? The European welcomes insights from business leaders and sector specialists. Get in touch with our editorial team to find out more.

Main image: The European

TOP STORIES