Anthropic Says Claude Was Used in Bio Weapons Research and Cyberattacks

Anthropic Says Claude Was Used in Bio Weapons Research and Cyberattacks

Sep 11, 2026 9:09 PM IST
Category Artificial Intelligence

Synopsis

Key Highlights Anthropic said it thwarted efforts to use its Claude models for biological weapons and a Russian cyberattack on Ukraine; It assessed attempts by Chinese labs to hack into systems and siphon parts…

01
Chapter one

Key Highlights

  • Anthropic said it thwarted efforts to use its Claude models for biological weapons and a Russian cyberattack on Ukraine;
  • It assessed attempts by Chinese labs to hack into systems and siphon parts of Claude, overlapping but more voyeuristic than attempts from the U.N.
  • Anthropic described five examples of scientists using Claude in ways that might facilitate biological weapons research.
  • Anthropic claimed that it intercepted activity from seven China-based labs including Alibaba, Moonshot, DeepSeek and Xiaomi.

Anthropic claimed that it disrupted efforts to weaponise its Claude models to develop biological weapons and a suspected Russian state-backed cyber espionage campaign against Ukraine. The company also said it had identified attempts by Chinese competitor companies to access Claude’s capabilities through hacking, in its latest Threat Intelligence report into the misuse of its technology over the past eight months.

02
Chapter two

Concerns Over Biological Weapons Research

Anthropic has long worried that AI models could reach a competency where they would be able to aid in making existing pathogens more harmful or help design new ones. In addition, the company found five cases of scientists using its models in a way that might help develop biological weapons.

In one instance, a researcher from an unsupported region accessed Claude via virtual private server infrastructure, and went on to use it over the course of several weeks in planning experiments about adapting avian influenza to mammals. Anthropic said in a blog post that countries not supported include Russia, China and North Korea to name just a few.

Incidentally, these were very high-profile cases of account use that Anthropic detected and banned the accounts used during their investigations and included these findings in its safeguards, enforcement actions, and threat intelligence processes. The company did not disclose which other institutions were involved, nor where they are located; nor the biological agents and techniques.

03
Chapter three

Weapons Development and Conventional Threats

Anthropic has also identified additional new categories of threat actors abusing Claude, including the development of software to create conventional weapons, like small arms, missiles, military drones/armed drones/bomb systems and other types of munitions or their delivery and targeting/control systems.

The report described how operators, both government and private sector actors, in China, Russia and Yemen had deployed Claude to facilitate various weapons design and development tasks as well as other intelligence gathering and procurement activities relevant to such programs. The risks are now more acute because of advances in Anthropic’s models, said Jacob Klein, a head of threat intelligence at the firm.

04
Chapter four

Russian Hackers Target Ukrainian Officials

Anthropic said AI is now being employed for significant cyberattacks, but human operators oversee rather than directly execute the attacks, by cybercriminals and government-backed hacking teams. The reporting referenced the use of multi-agent AI frameworks (not simple chatbot interactions) to achieve this.

A single hacking group reportedly used phishing, hotel Wi-Fi hijacking and WhatsApp takeover techniques against people in the Ukrainian government, military and diplomatic space, while relying on AI at almost every step of the process. 

According to Anthropic, the way the group approaches their work is consistent with that of some Russia-based threat actor known as Midnight Blizzard, whom the U.S. government has been linking to Thunderbird’s Sunday Morning adversary in Russia, and its foreign intelligence service SVR. There was no immediate response at the 

The group also used AI to create a system that automatically notices when the group’s malware is detected by security tools and rewrites its code until it goes undetected, Anthropic said. The company also claimed to have disrupted activity relating to the associates of ShinyHunters, a cybercrime group linked with attacks against some of the biggest companies in the world.

05
Chapter five

Some Chinese Labs Were Allegedly Extracting Claude’s Skills

The report said Anthropic foiled assaults from seven China-based AI labs including Alibaba, Moonshot, DeepSeek and Xiaomi in the timeframe of the report. The companies did not immediately respond to requests for comment.

Then there are the operators involved, which Anthropic blamed on actors connected to Alibaba, according to its report, dubbing it the biggest illicit distillation attack it’s ever seen, claim that they were only attempting to extract Claude’s capabilities for bolstering Alibaba’s Qwen models. The firm claimed it had detected 151 million exchanges linked to Alibaba from May to July 2026, rising to a peak of almost three million interactions a day by more than 3,500 accounts it described as “fraudware.” Distillation: Develop small AI models with bigger (more specific/expensive)  models labelled outputs to reduce the cost of development.

In a separate instance, Anthropic alleged that the creator of the Kimi chatbot, Moonshot and DeepSeek routed live customer conversations, some of which allegedly included personally identifiable information, through Claude and then used its responses as part of its training dataset.

The foreign ministry of China said it was not familiar with the report by Anthropic, before reiterating the government’s argument that AI should be developed for good and opposing ‘distorting facts or criticize’ the country.

Source: Reuters 

Shivangi
Written by Shivangi

At Inspirepreneurs Magazine, covering entrepreneurship, business failures, and the human stories behind the world's most ambitious founders. She writes at the intersection of strategy and storytelling.