Anthropic says state-linked groups are increasingly using its Claude AI models for cyber espionage, surveillance and military-related operations, showing how generative AI is moving beyond assisting with isolated tasks to becoming part of broader operational workflows. The findings come from Anthropic’s latest threat intelligence report, covering malicious activity it identified and disrupted between December 2025 and August 2026.
One of the most significant cases involved a suspected Russia-linked group that used Claude across a cyber-espionage campaign targeting more than 20 government, defence, intelligence and diplomatic organisations. Anthropic said the AI was used across multiple stages, including target research, phishing infrastructure, credential theft and data processing. AI agents were also used to help adapt malicious tools after security products detected them.
Anthropic also reported Iran-linked activity involving reconnaissance of US military and naval targets, alongside separate surveillance operations connected to Iranian security-linked groups. Elsewhere, the company said China-linked actors used Claude for intelligence gathering, surveillance-related work and some military research. Reuters reported additional cases involving weapons-related software and research, although several of these assessments are based on Anthropic’s own investigation and attribution.
The bigger shift is automation. Rather than simply generating a phishing message or piece of code, AI systems can now coordinate parallel tasks, process large volumes of information and help operators adjust an operation as it develops. Anthropic said human operators still selected targets and reviewed results, but increasingly delegated the work between those steps to AI.
Anthropic said it banned accounts linked to the identified activity, strengthened detection systems and shared relevant intelligence with authorities and industry partners. The findings suggest cybersecurity teams may increasingly face adversaries whose advantage comes not from entirely new attack techniques, but from using AI to execute familiar ones faster, at greater scale and with fewer specialised operators.
Filed by
Startup Unplugged
