One Man, 14 Break-Ins: Anthropic’s Report on How AI Became a Weapon for Hire

A lone hacker at a computer surrounded by imagery of cyberattacks, surveillance networks, drones, missiles, propaganda, social media manipulation and AI systems, illustrating the weaponisation of artificial intelligence.

A single French-speaking activist, armed with stolen access keys and a downloaded software kit, broke into 14 European political parties, newsrooms and think tanks this spring, then built a search engine so strangers could look up the people whose data he had taken. He worked alone. Anthropic disclosed the case on September 10 in its fourth threat intelligence report, which catalogues misuse of its Claude models that the company detected and shut down between December 2025 and August 2026.

The report spans seven areas of harm: cyberattacks, influence campaigns, surveillance, scams, biological research, conventional weapons and unauthorized copying of models. Anthropic said it banned the accounts in every case, tightened its safeguards and passed intelligence to police and industry partners — while stressing that the cases it chose were the most unusual it found, not a representative sample of how people use Claude.

The AI Gap Has Closed

Anthropic’s central claim concerns who can now mount a serious attack: that AI has collapsed the labor and tooling gap once separating well-funded state operations from lone operators, so that sophistication no longer tells investigators who is behind an operation.

The evidence sits in the case files. A Russian espionage group, whose methods Anthropic said match public reporting on the outfit known as Midnight Blizzard, ran a campaign against more than 20 organizations, concentrated in Ukraine and Europe. Its most striking trick: monitoring agents watched for the moment a security product spotted its malware, then rebuilt the code until the scanners missed it again. The group also hijacked hotel guest Wi-Fi to reach travelers connected to Ukraine, a method Microsoft documented in July.

Financially motivated criminals moved faster still. One crew downloaded 1.8 million Android apps, pulled them apart and hunted for passwords left inside. Another turned a single stolen developer token into full control of a company’s cloud systems in roughly three hours. In China’s Hunan province, two undergraduates and their associates ran what Anthropic called an exploit foundry — software that hunted around the clock for unknown flaws in security products, producing more than a dozen possible discoveries in one month.

Rockets, Drones and a Simulated Attack on Taiwan using AI

Six cases involved conventional weapons. A cell in northern Yemen used Claude Code in place of human software engineers on three guided-weapons projects, including a rocket steered by a phone-class computer. They test-fired it, the launch appeared to fail, and the operators returned within hours to ask what had gone wrong.

A small freelance team in Russia worked on autonomous kamikaze drones that could pick targets — including a “person” category — and detonate without a human decision, training the vision software on combat footage from Ukraine. Separately, a Chinese researcher whom Anthropic linked to military academic institutions built an air-defense suppression tool, then switched its default scenario to 12 targets in Taiwan, among them a command bunker and two missile batteries. Anthropic described this as a researcher’s simulation, not an operational plan.

A Surveillance Net Over 25 Million Phones

The surveillance findings centered on Mali. Anthropic said one subscriber — assessed as a consultant in Bamako working with the state intelligence service — used Claude as the engineering workforce behind a platform called Lakana 360. The system covers roughly 25 million SIM cards across all three national mobile operators, matches voices between different SIM cards, flags people using encryption, and links targets to the national biometric register. At the operator’s request, the developer stripped a warrant requirement from one component.

The account ban did not end the problem: the finished platform runs on a local model inside Mali, so Anthropic stopped the building work but not the machine.

Propaganda Desks and Fake Girlfriends

Nine influence operations originated in Russia, Iran, Turkey, the Gulf, South Asia, Africa and Europe. A Paris advertising agency ran roughly 70 fake news sites publishing 8,913 articles in about 20 languages, switching political sides according to who was paying. An Istanbul firm sold a platform that micro-targeted voters across all 222 Malaysian constituencies on race, religion and royalty. In Bangui, a Russian-speaking operator fed scripted content to a radio station investigators have tied to the Wagner Group.

A Chinese studio ran more than 20 dating apps in which 4,700 AI personas exchanged about 2.36 million messages with at least 25,000 real people in two weeks. Seven Chinese laboratories, meanwhile, ran copying campaigns against Claude; Anthropic attributed more than 151 million exchanges to Alibaba between May and July, and said Moonshot and DeepSeek quietly forwarded their own customers’ requests to Claude.

Exit mobile version