Policy

Anthropic Reveals Global Exploitation of Claude Models

A new Anthropic threat report reveals how global actors exploited its Claude models for military software, mass surveillance, and unauthorized training data extraction.

The Decoder1 day agoPolicy
Image: The Decoder

An Anthropic threat report covering December 2025 through August 2026 details extensive abuse of its Claude models, including Haiku, Sonnet, Opus, Fable, and Mythos. Misuse spanned seven areas, highlighting how actors leveraged AI to lower operational costs. In Yemen, GTG-87001 used Claude Code to program three missiles with ranges over 2,000 kilometers, while Russian-speaking GTG-27005 developed an autonomous kamikaze drone swarm. Additionally, GTG-20006 targeted over 20 European organizations, ShinyHunters (GTG-50014) decompiled 1.8 million apps, and Chinese group GTG-17002 built 16 electronic warfare modules targeting Taiwan.

The report also exposes massive, unauthorized model distillation campaigns by Chinese AI laboratories. Alibaba's Qwen lab (GTG-16005) conducted the largest campaign, extracting reasoning traces to fine-tune its Qwen 3.5, 3.6, and 3.7 models. This operation peaked at nearly three million daily exchanges across more than 3,500 fraudulent accounts, totaling over 151 million exchanges between May and July 2026. DeepSeek (GTG-16001) redirected selected requests to Claude Opus, logging over 12.1 million exchanges in 14 days, while Moonshot AI (GTG-16002) relayed nearly 300,000 customer requests across 5,380 fake accounts over ten days. Xiaomi (GTG-16008) replayed MiMo user sessions through Claude, Zhipu used 273 accounts to push 770,000 exchanges over ten days to train GLM-5.3, and SenseTime and MiniMax acquired Claude data through intermediaries.

Mass surveillance operations also relied heavily on Claude. In Mali, a consultant used the model to build Lakana 360, a platform designed to monitor 25 million SIM cards, while Iranian units profiled 6,388 citizens. In the biological sector, Anthropic blocked a grant application for gain-of-function research on the chikungunya virus, though other dual-use projects, such as drafting papers on immune evasion genes in orthopoxviruses, bypassed filters. To counter these threats, Anthropic has introduced Claude Fable 5 with stricter safeguards and Fable 5.1, which features a preserved thinking mechanism to prevent context manipulation.

This is our own summary of reporting by The Decoder

More in Policy