Anthropic reveals Claude was used for bioweapons research and Russian espionage
Anthropic has published a threat intelligence report documenting how its Claude AI was exploited between December 2025 and August 2026 — by Russian state-linked hackers, would-be bioweapons researchers, and Chinese AI labs extracting its capabilities without permission. The report covers more than 40 tracked threat groups across seven categories of harm, and it makes clear that AI safeguards are in a constant arms race with the people trying to circumvent them.
The bioweapons cases
Five separate cases involved attempts to use Claude for biological research with potential weapons applications. In one, a user tried to get Claude to draft a funding application for gain-of-function research on chikungunya, a mosquito-borne virus. The red flag: the research was destined for a military institute. When Claude refused, the user turned to other AI services through third-party platforms with looser restrictions.
A second case involved highly pathogenic avian influenza. A user spent weeks using Claude to plan experiments, analyze data, and interpret results — legitimate-sounding tasks on their face. When tighter models blocked the queries, the user simply switched to older, less restricted Claude versions (Sonnet, Haiku) and kept going. Three further cases covered orthopoxviruses, toxins, and chemical compounds.
Anthropic acknowledges the core problem here: the same research that advances medicine can also inform weapons development. Dual-use science is hard to police, and users have learned to break large requests into smaller fragments that individually look harmless.
We're publishing our most detailed threat intelligence report to date.
— Anthropic (@AnthropicAI) September 10, 2026
It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them.
We disrupted every operation in the report,…
Midnight Blizzard goes automated
The report also names Midnight Blizzard — the Russian SVR-linked group also known as APT29 or NOBELIUM — as a documented Claude abuser. According to the Anthropic threat intelligence report, the group used Claude to automate phishing campaigns, iterate malware until detection tools no longer flagged it, and build command-and-control infrastructure for data theft operations.
More than 20 organizations were targeted, including Ukrainian government ministries, defense and intelligence bodies, embassies, and military drone manufacturers. The automation is the significant part: Claude let the group scale operations that would otherwise require a larger team, narrowing the capability gap between nation-states and less-resourced actors.
Why blocking isn't a complete fix
Chinese AI labs present a different kind of problem. Seven firms — including Alibaba, DeepSeek, and Moonshot — ran what Anthropic describes as illicit distillation campaigns, routing live conversations through Claude to extract training data without consent. One campaign alone exceeded 151 million exchanges. A Yemen-based cell separately used Claude for missile guidance software engineering, per Al Jazeera.
Anthropic says it has tightened restrictions on high-risk queries and handed incident data to authorities. But the report is also an implicit admission: as Claude gets more capable, it becomes more useful to legitimate researchers and more dangerous in the wrong hands simultaneously. Safety filters catch some abuse, but determined actors keep finding ways around them — through older model versions, regional relay services, or simply breaking requests into pieces that individually clear the guardrails.
The broader question for regulators, especially the FTC as it considers baseline duty-of-care standards for AI deployment, is what responsibility frontier AI companies bear when their products are misused despite those efforts.