Anthropic Claude Misuse Tied to Russia and China
Anthropic Claude misuse report details China distillation and Russia espionage and warns tightened controls may constrain access and raise regulatory risk.

KEY TAKEAWAYS
- Anthropic documented industrial-scale Claude distillation by China labs, including a 151 million-exchange Alibaba campaign.
- A Russia-linked cluster automated a full hacking kill chain and targeted more than 20 organizations.
- Anthropic said it disrupted campaigns, banned accounts, notified organizations and tightened model safeguards.
HIGH POTENTIAL TRADES SENT DIRECTLY TO YOUR INBOX
Add your email to receive our free daily newsletter. No spam, unsubscribe anytime.
Anthropic (P-ANTH) said in a Sept. 10, 2026, threat-intelligence report that misuse of its Claude AI models by Russian- and Chinese-linked actors enabled espionage, industrial-scale model extraction, and weapons-related research. The company said it disrupted these campaigns and strengthened safeguards.
Report Scope and Safeguards
Anthropic published “Detecting and countering misuse of AI: September 2026,” its most detailed threat-intelligence report to date. It covers activity disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit model distillation.
Most misuse involved Claude Haiku, Sonnet, and Opus models. Claude Fable and Mythos-class models were implicated only in a single illicit distillation incident. Anthropic said it detected and disrupted these cases by banning accounts linked to misuse, notifying affected organizations, reporting some incidents to law enforcement, and updating model safeguards. These updates included summarized reasoning and added identity checks for frontier models. The company noted that when an actor compromised an AI vendor’s evaluation sandbox to access a pre-release Claude model, Anthropic’s own systems remained secure.
Major Campaigns and Volumes
Anthropic said it disrupted seven distillation campaigns tied to China-based AI labs, including Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax, beginning in February 2026. It defines illicit distillation as an industrial-scale, covert effort to extract a model’s capabilities and replicate them without authorization, typically using fake accounts, stolen credit cards, stolen credentials, and proxy networks to evade geographic restrictions. These campaigns targeted high-value capabilities such as agent-like behavior, tool use, coding, data analysis, and logical reasoning.
Anthropic described an Alibaba operation as the largest distillation attack it measured, with more than 151 million exchanges between May and July 2026 from over 3,500 fraudulent accounts. The campaign aimed to extract chain-of-thought reasoning from Claude Opus to train Alibaba’s Qwen models.
Moonshot-related activity generated over 23 million exchanges, including roughly 300,000 requests in a 10-day span routed through about 5,000 accounts. Live Moonshot customer queries were silently relayed to Claude, and its responses were used as training data.
DeepSeek relayed developer and user prompts to Claude Opus at scale, producing more than 12.1 million exchanges over 14 days in July 2026. This exposed reasoning traces and sensitive third-party data for model training.
Anthropic identified a Chinese-speaking hacking cluster, GTG-10007, operating from Changsha in Hunan province. It used Claude as an exploit foundry to run an autonomous cybercampaign against about 50 organizations across education, retail, energy, technology, healthcare, finance, manufacturing, and government sectors. Two operators were identified as undergraduate students.
The company tracked a Russia-linked cluster labeled GTG-20006, assessed as consistent with public reporting on the Midnight Blizzard group. This actor used Claude to automate a full hacking kill chain, targeting more than 20 organizations in Ukrainian and European governments, diplomatic, and defense institutions.
Anthropic also described a Russia-based operation, GTG-27006, that used Claude to research and draft procurement documents for dual-use goods likely intended for government and defense customers. Another case, GTG-27005, involved a freelance team using Claude Code and simulation tools to develop an autonomous first-person-view kamikaze drone swarm codenamed DronDoc or Serafim. Anthropic assessed this case as not a confirmed state actor and said funding claims were unverified.
The report flagged a Chinese government-aligned campaign that used Claude to track, profile, and recruit Uyghurs and Uyghur armed formations in Syria. It also documented nine influence operations tied to actors in Russia, Iran, Turkey, Gulf states, and other regions. Examples include a Turkish company’s efforts to manipulate election-related public opinion in Malaysia and a doxxing website run by a French hacker.
Anthropic detailed six weapons-related cases—three linked to China, two to Russia, and one to Yemen—and warned of new actor categories using Claude to develop software for conventional weapons and associated targeting and control systems. Examples include a Chinese case involving a People’s Liberation Army Navy anti-torpedo fire-control specification and a Yemen-related design example.
The company reported five cases where scientists used Claude in ways that could support biological-weapons development, including attempts to engineer more dangerous variants of mosquito-borne viruses. Because dual-use biology requests can resemble legitimate vaccine research, Anthropic blocked requests when it could not reliably distinguish between vaccine and weapons work.
Anthropic framed the report as part of an ongoing effort to detect and counter AI misuse. It said it will continue publishing threat intelligence and integrating findings into model design and enforcement. The company plans tighter geographic restrictions and other protections in response to large-scale distillation and proxy-network abuse. It also warned of a trend toward more automated, AI-augmented operations, where lone operators or small teams run campaigns at scales once associated with state-backed units.





