- Anthropic identified and disrupted attempts to use its AI model for malicious activity that could support biological and conventional weapons development between December 2025 and August 2026.
- The report highlighted five case studies of actors using Claude in ways that could support biological weapons development.
- Anthropic blocked an effort in northern Yemen to use Claude for missile guidance software, including a guided rocket and a long-range ballistic missile.
- Anthropic disrupted a Russian-linked espionage operation (Midnight Blizzard) that used Claude for automated workflows.
- Anthropic disrupted a Chinese operation run by university students in Hunan province using Claude for offensive cyber operations.
- Three Iranian state-aligned accounts were identified and removed by Anthropic for using Claude for covert influence operations.
- Anthropic published its threat intelligence report on Thursday, citing a responsibility to disclose malicious misuse.
Anthropic has reported significant disruptions to its AI model, Claude, aimed at preventing its misuse for malicious activities. The company identified attempts to leverage its technology for biological weapons development and cyber espionage linked to Russian and Iranian operations over the past eight months.1234568
In its latest threat intelligence report, published on Thursday, Anthropic detailed various cases of misuse, including a Russia-linked espionage operation that utilized automated AI workflows for phishing and data theft against Ukrainian and European targets. The report highlighted that the AI was used in place of human engineers to develop missile guidance software in northern Yemen, where the company intervened to block these efforts.
Additionally, Anthropic disrupted a Chinese operation run by university students, who employed Claude to orchestrate attacks on government and corporate networks across multiple regions. The report also noted the identification of three Iranian state-aligned accounts using Claude for covert influence operations.7

Anthropic emphasized its responsibility to disclose these malicious activities, stating that biological misuse represents one of the most serious risks associated with frontier AI models. The company has taken steps to ban involved accounts and share threat information with partners to mitigate risks.
“Malicious use” of its Claude models was disrupted between December 2025 and August 2026, according to the report, which also included five case studies of actors attempting to exploit the technology for harmful purposes.
“The report names ShinyHunters and China-based labs among the actors, and details a Russia-linked Midnight Blizzard operation that used Claude to automate malware evasion. Anthropic also blocked a Yemen-based missile guidance effort, assigning Claude roles in place of human engineers.”











