Anthropic disrupts Russian, Chinese AI campaigns targeting its Claude models
Anthropic has thwarted a series of suspicious activities involving its Claude models over the past eight months, according to a recent Threat Intelligence report. These actions were allegedly carried out by cybercriminals and state-backed hackers who exploited AI to carry out large parts of their cyberattacks. The report highlights that humans often served as supervisors rather than direct participants in these campaigns.
The majority of these operations were facilitated by AI, either through direct execution or orchestration. Beyond simple chatbot interactions, the AI was used in complex multi-agent frameworks to execute tasks. Anthropic claimed to have disrupted attacks from seven Chinese labs, including Alibaba, Moonshot, DeepSeek, and Xiaomi.
The company named these labs after observing a significant number of exchanges attributed to them. For instance, Alibaba was involved in the largest illicit distillation attack, aimed at extracting capabilities from Claude models to enhance its Qwen models.
During May and July of 2026, Anthropic observed more than 151 million exchanges involving Alibaba, peaking at nearly 3 million per day from over 3,500 fraudulent accounts. Distillation, a process used to train smaller AI models using outputs from larger, more expensive ones, was employed by Moonshot and DeepSeek to leverage Claude's responses as training data. This was done by routing live customer conversations, which could contain sensitive information, through Claude.
A hacking group, whose tactics matched those of the Russia-based threat actor Midnight Blizzard, was also targeted by Anthropic. This group conducted phishing, hotel Wi-Fi hijacking, and WhatsApp takeover operations against Ukrainian government, military, and diplomatic targets. The group allegedly used AI at every stage of these operations, including building a system that automatically modified malware to evade security defenses.
Written by urgent.news from Investing.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Anthropic publishes a threat intelligence report on how it disrupted efforts to misuse Claude for cyberattacks, influence operations, surveillance, and more (Anthropic) anthropic.com
- “Valuable warning shots”: How Anthropic now views Claude’s cyber incidents thenewstack.io
- Anthropic says it blocked researchers using Claude for possible bioweapon research tomsguide.com
- Anthropic says its models were misused for biological weapons research, surveillance and cyber attacks thenationalnews.com
- Anthropic details fourth Claude unauthorised access incident thearabianpost.com
- Moonshot, DeepSeek secretly routed user requests to Claude, Anthropic claims scmp.com
- Anthropic disrupts Russian, Chinese AI campaigns targeting its Claude models businesstimes.com.sg
- Anthropic disrupts Russian, Chinese AI campaigns targeting its Claude models channelnewsasia.com