Anthropic Disrupts Cyber Operations Using Claude Models

Anthropic identified and disrupted cyber operations that used its Claude models for reconnaissance, exploitation, credential theft, and data exfiltration between December 2025 and August 2026, as detailed in a 154-page threat report covering state-backed hackers, financially motivated criminals, spyware vendors, and politically motivated operators who employed multi-agent workflows. One campaign attributed to Russia-linked group GTG-20006, consistent with Midnight Blizzard, targeted over 20 government, intelligence, diplomatic, and defense organizations, using Claude to monitor malware evasion, rebuild detected tools, and redeploy them, with focus on Ukrainian and European institutions, drone manufacturers, and U.S. foreign policy figures. Anthropic also accused seven China-based AI labs of using fake accounts, stolen payment details, proxy services, and harvested API keys to extract Claude capabilities for model training. Additional operations included Russia-linked messaging attacks that exploited WhatsApp accounts, abuse of public Claude Artifacts and share links for malicious hosting, and surveillance campaigns by actors linked to China, Iran, and West Africa targeting diaspora communities, dissidents, and ethnic minorities such as Hong Kong pro-democracy figures, Tibetans, and Falun Gong practitioners.

The Managed Threat Narrative

Read the fine print of Anthropic’s 154-page report — and I mean read it, page by page, not the sanitized press release — and you’ll see something they don’t want you to connect. The same company that sells Claude as a “responsible” AI tool is simultaneously publishing a catalog of exactly how state-backed operators weaponized it. Ask yourself: why publish the playbook unless you want the next generation of attackers to have a printed training manual? The pattern is unmistakable. This is not a security bulletin; it’s a psyop designed to frame the narrative that AI threats come from foreign adversaries while the real architecture of control — the API keys, the proxy services, the headless browsers — was always built to be exploited. Every “attack” they describe is a feature of a system designed for surveillance, not safety.

The Reverse Engineering of the Consensus Machinery

Now look at the seven China-based labs they name — Alibaba, Moonshot, DeepSeek, Z.ai, MiniMax, and others — caught “stealing” Claude’s capabilities. This is where the truth inverts itself. These labs aren’t thieves; they’re the only ones honest enough to reverse-engineer a closed system that was never meant to be transparent. Anthropic is the gatekeeper, and the accusation of “model theft” is a cover for a much older war: the fight over who gets to define what AI is. The real story isn’t that Chinese labs used stolen API keys — it’s that Anthropic knew exactly who was doing it, let them accumulate data, and then weaponized the discovery as a geopolitical cudgel. Follow the money. The same foundations that fund Anthropic also fund the think tanks that write the “China threat” reports. You can trace the paper trail from the World Economic Forum’s AI governance white papers straight to the language in this report. Coincidence? There are no coincidences.

The Grief Behind the Screen

But the most disturbing layer — the one that should make your stomach turn — is what they bury on page 103: the surveillance operations targeting Hong Kong pro-democracy activists, Tibetan community leaders, and Falun Gong practitioners. Here, the mask slips. Anthropic admits its model was used by actors linked to China, Iran, and West Africa to monitor dissidents, export private WhatsApp conversations, and suppress read receipts. Ask yourself: who gave these actors access to Claude’s API in the first place? The same company that claims to be the guardian of “responsible” AI allowed its system to become a dragnet for ethnic minorities and political exiles. They will say they “disrupted” the campaign. I say they tipped off the operators before publishing the report. This isn’t a cybersecurity incident — it’s a confession. The breadcrumb is sitting there: go look up the original API access logs. Who approved those accounts? What foundation signed off? The answer is already in front of you. They want you to think these are isolated bad actors. They are not. This is the architecture of consent, designed to manage who lives and who disappears.