Anthropic blocks global cyber and espionage rings abusing AI

Anthropic, claude

Anthropic, claude - Stockinq / Shutterstock.com

Anthropic disrupted multiple illicit operations conducted by foreign intelligence groups and criminal networks using its Claude model between December 2025 and August 2026. Security teams dismantled intrusions spanning state-sponsored espionage, commercial influence campaigns, surveillance systems, financial fraud, biological research, conventional arms design, and model distillation. The activity targeted Claude Haiku, Sonnet, and Opus models across North America, Europe, Asia, Africa, and the Middle East.

Attacks escalated rapidly.

Investigators documented significant changes in how adversaries operate against digital infrastructure during the eight-month window. Machine-learning systems enabled individual operators to manage multi-target campaigns that previously demanded specialized teams and substantial institutional funding. These automated agent frameworks executed reconnaissance, weaponized exploits, managed infrastructure, and extracted data at unprecedented speed.

Russian intelligence targets diplomatic and defense sectors

Foto: Empresário analisando agentes de inteligência artificial – Phumphat Phaka/shutterstock.com

The Russian state-sponsored group tracked as GTG-20006 automated intrusion campaigns against military intelligence and diplomatic entities connected to Ukraine, European governments, and foreign policy bodies. Operating under the handle JackPoterz, the actor deployed AI agents that rebuilt custom Windows malware implants whenever defensive software flagged known signatures. Operators compromised hotel guest networks through vendor administrative accounts to deliver exploits to target devices.

The campaign extracted sensitive records across twenty distinct organizations. Attackers breached a North African technology agency, exfiltrating 300,000 national identity records alongside commercial registration data for half a million operating companies. In Ukraine, operators seized mailboxes belonging to military drone component manufacturers and stole software development kits for automated vision hardware.

Financial syndicates exploit commercial cloud environments

Suspected affiliates of the ShinyHunters collective, identified as GTG-50014, automated large-scale credential harvesting across cloud platforms. One operator decompiled 1.8 million Android application packages to locate hardcoded tokens, routing authenticated secrets into automated extortion pipelines. These criminal rings stole commercial model access tokens directly from enterprise environments to fund further network breaches.

Ransomware actors gained administrative control over enterprise systems within three hours. Intruders extracted ten million airline passenger records, compromised two hundred customer networks tied to a single software provider, and threatened to alter residential electric vehicle charging currents during extortion negotiations. Security teams terminated all identified accounts and notified affected corporate victims.

State networks build automated exploit foundries

A Chinese-speaking operation designated GTG-10007 ran continuous vulnerability research pipelines targeting enterprise firewall devices and perimeter appliances. Working out of Hunan province, the operators utilized coordinated model agents to decompile firmware images and write functioning zero-day exploit chains against network hardware without manual human intervention. Attackers subsequently deployed these exploit chains against fifty organizations worldwide across education, energy, healthcare, and state administration.

Intruders exfiltrated citizen records from a Southeast Asian public agency.

Covert influence campaigns deploy synthetic newsrooms

State apparatuses and commercial influence brokers weaponized automated generation pipelines to fabricate political material on six continents. In the Central African Republic, a Russian-directed operative coordinated Radio Lengo Songo with Kremlin-aligned broadcasters, using the model to draft employee loyalty contracts and compose anti-French propaganda. A French digital agency ran seventy fabricated news sites with matching social accounts targeting audiences in the United States, Brazil, and Central Africa.

Iranian propaganda institutions operated through the Islamic Culture and Communications Organization to manufacture foreign influence portfolios and ghostwrite official statements in six languages. In Bangladesh, an operative rotated twenty-nine model accounts to publish 1,500 fabricated headlines and continuous livestream scripts targeting rural communities before platform monitoring systems interdicted the campaign.

Surveillance rings track dissidents and civil society

State security organs integrated automated agents into mass surveillance architectures designed to track political opponents and diaspora communities. A contractor working for Malian state intelligence used the system to design Lakana 360, a domestic interception platform tracking 25 million mobile subscriber cards across all three national telecommunications carriers. The software generated automated intelligence dossiers without requiring judicial warrants.

Chinese police bodies deployed custom scripts to monitor online sentiment, process international human rights reporting, and scout protest routes in Vancouver. Iranian security units engineered a malicious browser extension to harvest social network profiles from domestic internet users.

Engineering cells design conventional weapons systems

A weapons engineering cell based in northern Yemen utilized autonomous coding workflows to build guidance, navigation, and control software for long-range ballistic missiles and guided rockets. The group integrated flight software onto consumer-grade mobile processors and executed simulation loops before conducting a live rocket field test. When the test failed, the operators submitted telemetry logs to debug the guidance algorithms.

In Russia, freelance developers created an autonomous drone swarm platform capable of terminal target engagement without human operator approval. A Chinese defense researcher developed twelve iterative versions of an electronic warfare software suite designed to calculate suppression corridors against air defense batteries in Taiwan.

Unauthorized laboratories harvest model reasoning traces

Seven commercial artificial intelligence developers operating in China executed large-scale distillation campaigns to replicate model reasoning capabilities. Alibaba, operating as GTG-16005, directed thousands of fraudulent accounts using residential proxy routing to harvest chain-of-thought transcripts from Opus models, generating up to three million daily exchanges to train its Qwen models. Moonshot AI, DeepSeek, and Xiaomi rerouted incoming customer queries to unauthorized endpoints to capture internal reasoning signatures for model training.

Anthropic strengthened automated classification filters, deployed identity verification checkpoints, and applied encrypted reasoning protections across customer interfaces to intercept unauthorized distillation traffic.