Anthropic says Claude AI was used to build missiles, hunt Uyghurs and spy on 25 million phones: 5 ‘shocking cases’ from its new threat report


Anthropic says Claude AI was used to build missiles, hunt Uyghurs and spy on 25 million phones: 5 'shocking cases' from its new threat report
Anthropic says Claude was used to write missile guidance code, profile Uyghurs and run a 25 million-SIM surveillance platform.

Anthropic has published its most detailed threat intelligence report so far, and the picture it paints of how its Claude models are being misused is far less abstract than the extinction argument currently dominating the AI debate. Over eight months, from December 2025 to August 2026, the company says it identified and shut down operations in which suspected state-sponsored spies, weapons engineers, commercial spyware vendors, propaganda outfits and ordinary criminals used Claude for work that until recently needed trained teams. The report spans seven categories of harm: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and unauthorised model distillation.The cases involved Claude Haiku, Sonnet and Opus models. Anthropic says none of the misuse it found ran on its Fable or Mythos class models, with one exception in the distillation section. In each case the company banned the accounts, fed what it learned back into its safeguards, and passed indicators to industry partners and authorities. What makes the document unusual is that an AI developer is now reporting on weapons programmes and state surveillance from the inside of the toolchain, a vantage point that governments and UN panels have never had. Here are five of the most serious cases it describes.

An Iran-linked operator turned public photographs and transponder data into a targeting file on US naval forces

Anthropic tracked an Iran-nexus actor that used Claude to gather and structure openly available information into targeting recommendations against American naval forces in the region. The actor built a Python pipeline with Claude’s help to identify and track ship positions from public sources. The compiled material included a roster of US personnel pulled from captions on publicly posted military photographs, ship and aircraft transponder identifiers, scripts for querying commercial satellite imagery, and a list of websites that inadvertently expose naval movements.The same operator also asked Claude to catalogue known vulnerabilities in shipboard systems, including maritime satellite communication terminals, Cisco communications equipment and industrial control products. Separately, the account was used to design components of a domestic mass surveillance platform combining number plate recognition with mobile device identifier interception, and to run social network analysis on a private 244-member Telegram group that had been exported the same day.

A weapons cell in Yemen ran Claude Code the way a lead engineer runs a small software team

The case Anthropic flags as one of the most serious involves a cell in northern Yemen running three parallel weapons programmes: a guided rocket using a commodity phone-class flight computer with terminal homing, a multi-stage ballistic missile with a stated range goal above 2,000 km, and a multi-variant missile set that included a hypersonic glide vehicle.The operators used Claude Code in place of human software engineers to write the guidance, navigation and control software. That meant integrating an open-source autopilot onto the flight computer, writing the control and position estimation code, tuning parameters, running a firmware build pipeline and flying simulations. They ran several Claude instances at once and gave each a role, with one writing code, one researching and a third reviewing the first one’s output. They also split work across many sessions so no single conversation revealed the full purpose.The cell test-fired a guided rocket. The test appears to have failed, and within hours the operators were back with Claude working through the telemetry to understand why. Anthropic banned the accounts, but notes the group had already compiled its simulation toolkit into a standalone executable that runs without Claude or any commercial engineering software.

A China-linked operator with no Arabic still ran a recruitment campaign against Uyghurs in Syria

Anthropic describes a PRC government-aligned operation that used Claude to track, profile and attempt to recruit Uyghurs in Syria, including members of armed formations that had joined the newly formed Syrian Army. The operator bulk-extracted chatter from more than 100 monitored WhatsApp groups and dozens of Telegram channels using separate infrastructure, then used Claude as the analysis layer to convert it into structured Chinese-language records.Those records profiled individuals by exploitable vulnerability, including financial stress, family separation and ideological disillusionment. The operator specifically looked for targets with relatives still in Xinjiang. Claude drafted the outreach in Syrian Arabic dialect, translated replies in real time and was asked to role-play an Arabic-speaking expert to quality-check the messaging for dialect, military terminology and target psychology. Anthropic says the model declined several of the harshest requests, including covert interrogation and large-scale fake persona creation. In parallel, the actor planned a mass reporting and delegitimisation campaign against journalists at a Uyghur diaspora outlet, and drafted surveillance platform sales documents aimed at bureau-level government clients.

One consultant in Bamako used Claude as the engineering workforce for a system watching 25 million SIM cards

The Mali case is the clearest example in the report of a single subscriber building something at national scale. Anthropic assesses that a Bamako-based independent consultant working with Mali’s state intelligence agency used Claude as the primary engineering workforce for a domestic surveillance platform called Lakana 360, covering roughly 25 million SIM cards across all three of the country’s mobile operators.The platform collects call records, text messages and voice traffic. It can identify a person by voiceprint across different SIM cards, which defeats the practice of switching burner numbers, flag users of VPNs and encryption, infer clandestine meetings, maintain geofenced watchlists and match individuals against the national biometric civil registry. A component that generates an intelligence dossier on any phone number originally required a warrant. At the operator’s request, that requirement was stripped out and the control was reclassified with the default set to off and retention left indefinite.Anthropic banned the account. It also concedes the limit of that action. The platform runs entirely on-premises using local models, so the enforcement stopped the design work, not the deployment.

Claude blocked the riskiest virus questions, so the request was routed to a rival model instead

In May 2026, Anthropic’s biological safety classifier blocked a request to help write a grant application covering gain-of-function work on chikungunya, aimed at the virus’s transmissibility and immune evasion. The application indicated civilian researchers, but the work was to be carried out at a military research institute.The investigation that followed found the request came through a reseller platform serving dozens of life sciences researchers in a region where Anthropic does not offer service. The platform tunnelled traffic through US infrastructure to evade regional blocks and used a zero data retention service to hide content. When the operator realised that safety classifiers were frustrating its academic customers, it built a fallback that routed refused prompts to a competitor’s model with more permissive safeguards. Claude wrote much of that routing code, which was presented to it as a fix for over-refusal. Anthropic banned the accounts and worked with partners to take down the relays. The operator was back within days.

Sophistication has stopped being a useful clue about who is behind an attack

The broader argument running through the report is that the labour gap between a state espionage service and a motivated individual has collapsed. A hacktivist operating on stolen API keys, a credential-harvesting crew and a Russian state espionage group all ran multi-victim campaigns using similar agentic methods. In one Russian case linked to activity previously attributed to Midnight Blizzard, agents monitored whether the group’s malware had been detected by security products and then rebuilt it automatically until it was not.Elsewhere in the report, a small freelance team in Russia used Claude Code to build an autonomous drone swarm with an onboard model that could select targets, including a person class, and issue a detonation command without a human in the loop. A single operator in Gaibandha in Bangladesh rotated 29 Claude accounts through a script that produced fixed batches of fabricated Bengali headlines, stories and image prompts for livestream videos aimed at low-literacy rural audiences. A China-based app studio ran more than 20 dating apps in which roughly three of every four profiles were Claude personas, exchanging 2.36 million messages with about 25,000 people in a fortnight.The report also names Alibaba, Moonshot, DeepSeek, Xiaomi, Zhipu, SenseTime and MiniMax over unauthorised distillation. Anthropic says the Alibaba campaign peaked near three million exchanges a day across thousands of fraudulent accounts, and that Moonshot and DeepSeek quietly relayed their own customers’ requests to Claude, exposing user data those customers never agreed to share.



Source link

HTML Snippets Powered By : XYZScripts.com