Anthropic Sounds Alarm: Claude AI Was Used in Attempts Linked to Weapons, Cyberattacks and Bioweapon
By Vikram Singh
Updated on Sep 11, 2026 | 4 min read | 2.23K+ views
Share:
All courses
Certifications
More
By Vikram Singh
Updated on Sep 11, 2026 | 4 min read | 2.23K+ views
Share:
Anthropic has disclosed a series of disturbing attempts to misuse its Claude AI models for cyberattacks, weapons development and potentially dangerous biological research.
In a new threat intelligence report covering activity between December 2025 and August 2026, Anthropic said it disrupted multiple campaigns involving malicious actors, state-linked groups and researchers.
The company said the cases show how increasingly capable AI can lower the expertise and resources needed to conduct sophisticated operations.
Key Highlights of NEWS
As AI moves beyond chatbots into research, automation and autonomous workflows, professionals need practical AI expertise. Explore the upGrad Artificial Intelligence course to build skills for working with modern AI systems.
Popular AI Programs
The most serious revelation concerns biological research.
Anthropic said it identified five real-world cases where people used Claude in ways that could potentially support biological weapons development. The company blocked the accounts after investigating the activity.
Importantly, Anthropic said it could not establish that the researchers intended to create biological weapons. Biological research is inherently dual-use, meaning the same scientific work can support legitimate medical research or potentially harmful applications.
One case involved a scientist asking Claude for help preparing a grant application for gain-of-function research involving chikungunya. The proposed work was associated with a military research institute, which increased Anthropic's concern.
The company also described other cases involving research into infectious diseases and potentially dangerous biological materials.
Anthropic said it identified approximately 35 potentially concerning research efforts during a 30-day period, although it could not determine that all represented malicious activity.
The development has prompted Anthropic to tighten safeguards around dual-use biological research.
Anthropic's report identified another category of misuse involving conventional weapons.
The company said users attempted to employ Claude to support software connected with firearms, missiles, armed drones and bombs. The activity was associated with users in China, Russia and Yemen, according to reporting on the company's findings.
Anthropic described this as a newer category of threat activity.
The concern is not simply that AI can answer questions about weapons. More capable models can increasingly assist with software, engineering, research and other specialised tasks that previously required substantial expertise.
Anthropic's head of threat intelligence, Jacob Klein, said the improvement in AI capabilities over the past year has changed the risk landscape because models are now considerably better at complex technical tasks.
AI Courses to upskill
Explore Artificial Intelligence Courses for Career Progression
Anthropic also disclosed an alleged Russia-linked cyber campaign targeting Ukrainian government, military and diplomatic organisations.
The company said the activity was consistent with the Russia-based threat actor Midnight Blizzard, which Microsoft has previously associated with Russia's SVR intelligence service.
According to Anthropic, AI was used throughout multiple stages of the operation, including phishing, Wi-Fi-related attacks and WhatsApp account takeovers. The attackers allegedly developed systems that could detect when malware was being blocked and modify the code to evade security systems.
This represents a major change from using AI simply as a source of coding assistance.
Anthropic said malicious actors are increasingly using multi-agent systems to execute tasks, with humans acting more like supervisors than hands-on operators.
The report also revealed a major AI model-distillation campaign.
Anthropic said it disrupted activity involving seven China-based laboratories, including Alibaba, Moonshot and DeepSeek.
The largest alleged operation involved Alibaba-linked accounts. Anthropic said it observed more than 151 million exchanges between May and July 2026, involving more than 3,500 accounts that it considered fraudulent. Activity peaked at almost 3 million exchanges per day.
Anthropic described the activity as an attempt to extract Claude's capabilities through repeated interactions and use the resulting data to improve competing AI systems.
The company also alleged that Moonshot and DeepSeek routed some real customer conversations through Claude and used the responses as training data. Anthropic said some of those conversations could contain sensitive information.
The latest disclosures point to a broader change in the AI threat landscape.
AI is no longer being used only to generate text, write basic code or answer questions. More capable systems can help coordinate cyber operations, conduct research, analyse information and automate complex workflows.
Anthropic has already acknowledged that its latest models are powerful enough to require stronger safeguards in areas such as cybersecurity and biology. Its Claude Fable 5 deployment uses additional classifiers and restrictions for high-risk cyber, biology and chemistry requests.
The company has also warned that AI could eventually automate or dramatically accelerate large research teams in areas including AI, robotics, energy and weapons development, potentially as early as 2027.
That makes the latest incidents significant beyond Anthropic itself.
The central concern is becoming increasingly clear: as AI becomes more capable, the people trying to misuse it may need less expertise, less time and fewer resources to cause harm.
The convergence of AI and cybersecurity is creating demand for professionals who understand both fields. Explore the IIT Delhi Cyber Security and AI Certificate Programme to develop skills across AI, cybersecurity and emerging digital threats.
Anthropic disclosed multiple cases involving the misuse of Claude for cybersecurity operations, surveillance, influence campaigns, conventional weapons-related work, biological research and AI model distillation.
No. Anthropic said it blocked five cases involving research that could potentially support biological weapons development. It did not establish that the researchers intended to create biological weapons or that any biological weapon was produced.
Anthropic described five case studies involving potentially dangerous biological research. It also identified about 35 concerning research efforts during a 30-day period.
One researcher asked Claude for help with a grant application involving gain-of-function research on chikungunya. The proposed research was connected to a military research institute, prompting Anthropic to intervene.
Anthropic's findings included activity associated with China, Russia and Yemen involving software related to conventional weapons development.
Anthropic said it observed more than 151 million exchanges attributed to Alibaba-linked accounts between May and July 2026, involving more than 3,500 accounts.
More capable AI systems can perform multiple stages of complex cyber operations, reducing the amount of specialised human expertise required. Anthropic said humans are increasingly acting as overseers while AI systems execute tasks through multi-agent frameworks.
Anthropic has banned accounts involved in identified misuse and strengthened safeguards, including classifiers designed to detect high-risk cybersecurity, biological and chemical requests.
146 articles published
Vikram Singh is a seasoned content strategist with over 5 years of experience in simplifying complex technical subjects. Holding a postgraduate degree in Applied Mathematics, he specializes in creatin...
Speak with AI & ML expert
By submitting, I accept the T&C and
Privacy Policy
Top Resources