
Claude is a series of large language models developed by Anthropic. It is also the name of the chatbot that uses these models to interact with users. Above, an illustration of Claude on June 18, 2026. Riccardo Milani/ Hans Lucas/AFP via Getty Images
Anthropic said on Sept. 10 that it had disrupted malicious campaigns involving the use of its artificial intelligence model Claude, including operations allegedly linked to threat actors in China and Russia.
The company said the threat actors include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals.
According to its report, most of the cyber operations detected between December 2025 and August 2026 were enabled by AI through direct execution or orchestration. Humans remained involved in selecting targets and reviewing exfiltration, it stated.
“The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration,” Anthropic said.
Among the threat actors named by the company was a group linked to Russia-based Midnight Blizzard. Anthropic alleged that the group used AI to attack military intelligence targets in Ukraine and Europe, as well as diplomatic and defense organizations and individuals connected to U.S. foreign policy.
Anthropic said it also disrupted distillation attacks against Claude from seven labs based in China, including operators allegedly linked to Alibaba, DeepSeek, Xiaomi, and Moonshot.
“We define illicit distillation as an industrial-scale, covert campaign to extract a model’s capabilities and replicate them in another model without authorization,” the company said.
This is a developing story that will be updated.









