Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations, the company said Thursday.
In a threat report covering activity between December 2025 and August 2026, Anthropic said it had observed “state-backed hackers, criminal groups and individual hacktivists” attempting to misuse its tools for cyber operations.
“In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate,” said the company.
The report has largely been applauded by security experts, although it notably doesn’t share broader figures regarding the scale of misuse Anthropic is detecting. But unlike similar reporting from the company’s rival OpenAI, Anthropic includes in-depth analysis of several campaigns and abuse types, alongside indicators of compromise (IOCs) that can be used by security teams.
Anthropic said the activity aligned with Midnight Blizzard — also known as BlueBravo, APT29 and Cozy Bear — a hacking group Western intelligence agencies have attributed to Russia’s Foreign Intelligence Service (SVR).
The hackers were observed to have compromised hotel Wi-Fi providers and changed DNS records to redirect travelers to attacker-controlled infrastructure. Anthropic cited Microsoft’s investigation linking the activity to Storm-2945, a sub-cluster of Midnight Blizzard.
The Russia-linked spies repeatedly targeted “members of the Ukrainian government, military, and diplomatic staff” alongside entities involved in the drone supply chain. After gaining access to the mailboxes from two drone-component manufacturers, the spies “targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system”
They then used Claude to reverse-engineer the drone’s vision system, “recovering its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product.”
“Military drone control and AI vision-related firmware appeared to be of particular interest,” the report said.
AI was also used by the group to monitor whether security products were detecting its hacking tools. “When their implants were flagged by security products, the actor used Claude to systematically identify, modify and redeploy the detected artifacts,” the report said.
“The result of the above is that AI has inverted the cost back onto defenders. Previously, defenders might have been able to slow an attacker’s operational tempo via the deployment of a new detection. Now, at least in theory, capable adversaries can ‘close the loop,’ bypassing traditional security detections faster than defenders can develop and deploy them.”
The impact this may have on cybersecurity could be dramatic. The Five Eyes intelligence alliance had warned in June frontier AI models will likely “exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.”
In other cases, suspected affiliates of the ShinyHunters cybercriminal group used AI to scan for credentials, map unfamiliar systems and steal data from their victims for extortion. Anthropic said that in one case, an operator moved from a stolen developer token to full administrative access to a victim’s cloud environment in about three hours.
Claude was also used by a Chinese-speaking group, including two operators identified as undergraduates at a Chinese university in Hunan. Among this group’s activities was maintaining “an autonomous vulnerability research program” whose “centerpiece was sustained research against a major security product” which it found several zero-day vulnerabilities in.
Anthropic also described a French-speaking hacktivist who used Claude in attacks on several European political parties, media organizations and think tanks. The hacktivist’s specific motivations were not described.
The company said the cases — in particular the hacktivist’s multi-victim campaign – show AI is narrowing the gap between state-backed groups and smaller operators by reducing the labor and expertise needed to run complex campaigns.
It noted, however, that AI is not replacing traditional attack methods, with phishing, stolen credentials, exposed services and software flaws remaining central to successful hacks.
Beyond cyber operations, the report covered other malicious uses including “influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation.”
“We’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services,” Anthropic said. “As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer.”
David Agranovich, a former Russia director at the National Security Council, said in a social media post the report highlighted how — similar to the commercial spyware industry before it — AI is lowering the barrier to entry for cyber operations and handing what used to be state-grade capabilities to actors who could never have built them.
Agranovich, who went on to found Meta’s threat-disruption team and now works on adversarial security at Google, cautioned that “some press coverage is going to frame this report as ‘Claude was used to [do bad thing]’ without noting that the only reason we know is because Anthropic dug into this and disrupted it.”
“If we don’t incentivize (or require) companies to share this stuff, they’ll stop,” he said.
