Anthropic Disrupts Russian, Chinese AI Misuse Campaigns
The AI company blocked 151 million fraudulent queries and exposed state-linked espionage operations exploiting its Claude models.
Anthropic Uncovers State-Backed AI Exploitation
Anthropic disclosed Thursday that it has disrupted multiple sophisticated campaigns targeting its Claude AI models over the past eight months, including a Russia-linked cyber espionage operation and systematic attempts by Chinese AI companies to replicate Claude's capabilities through mass extraction.
The company's latest Threat Intelligence report reveals a troubling evolution: adversaries are no longer simply using AI as an assistant but deploying it to orchestrate and execute substantial portions of cyberattacks, with humans serving primarily as overseers rather than hands-on operators.
Chinese Firms Accused of Mass Data Extraction
Anthropic identified seven China-based labs conducting what it termed "illicit distillation" attacks—attempts to extract Claude's capabilities to improve their own models. The largest operation allegedly involved Alibaba, which Anthropic said ran more than 151 million exchanges between May and July 2026, peaking at nearly 3 million daily queries from over 3,500 fraudulent accounts. The company claims these interactions aimed to enhance Alibaba's Qwen models.
Moonshot, creator of the Kimi chatbot, and DeepSeek allegedly took a different approach: routing live customer conversations—sometimes containing sensitive information—through Claude and using the responses as training data for their own systems.
Alibaba did not immediately respond to requests for comment, according to Reuters, which first reported these details.
Russian Intelligence Operation Targets Ukraine
A hacking group exhibiting tradecraft consistent with Midnight Blizzard, which the U.S. government has linked to Russia's SVR foreign intelligence service, allegedly conducted phishing campaigns, hotel Wi-Fi hijacking, and WhatsApp takeovers against Ukrainian government, military, and diplomatic targets. The operation used AI at nearly every stage, including building systems that automatically detected when malware was flagged by security defenses and rewrote code until it evaded detection.
Weapons Development and Cybercrime
Anthropic also flagged what it called "new categories of threat actors" misusing Claude for weapons-related software development. The company detected operators in China, Russia, and Yemen using the platform to develop code for firearms, missiles, armed drones, bombs, and their targeting systems, as well as supporting intelligence gathering and procurement for weapons programs.
The company additionally disrupted activity linked to ShinyHunters, a prolific cybercrime collective responsible for attacks on major corporations worldwide.
Why It Matters
This disclosure marks one of the most detailed public accounts of how state actors and commercial AI competitors are exploiting frontier AI systems. The scale—151 million queries in three months from a single alleged operation—demonstrates that model theft and misuse have moved from theoretical concern to industrial-scale reality. For enterprises evaluating AI vendors, Anthropic's transparency offers rare visibility into the threat landscape, while raising questions about how other AI providers are monitoring and responding to similar exploitation attempts.
Jacob Klein, Anthropic's head of threat intelligence, told Reuters that models have become substantially more capable over the past year at tasks like optimizing drone software or missile systems, creating risks that didn't exist when the technology was less advanced.
The details were first reported by Reuters.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
