Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research
In the latest installment of "my AI model is more dangerous than yours," Anthropic on Thursday warned that cybercriminals and state-sponsored hackers alike are using its Claude models to automate cyberattacks, build kamikaze drone swarms, conduct mass surveillance operations, and try to develop an even more dangerous version of a deadly mosquito-borne virus.
The baddies have come a long way since November, when an earlier Anthropic report documented Chinese spies using Claude to automate digital intrusions and steal sensitive data at a handful of critical organizations.
Now everyone from ShinyHunters to Russian freelancers is getting in on the illicit model usage.
This is not to say that Anthropic – nor any other frontier AI lab – plans to slow down its model development or testing initiatives, or take responsibility when its AI commits crimes.
It does, however, “hope that the findings in this report will help other developers recognize similar patterns on their own platforms, give governments and civil society a clearer view of how emerging threats take shape, and strengthen collective defenses.” The model maker’s latest very lengthy report on AI misuse covers activity Anthropic disrupted between December 2025 and August 2026 across seven “harm areas” where miscreants used – or attempted to use – Claude Haiku, Sonnet, and Opus models for evil.
These span cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation.
Anthropic also noted that its most powerful Claude Fable or Mythos-class models weren’t used, except in one distillation case.
Even without those most advanced systems, the case studies in the report highlight some pretty bad behavior.
Autonomous cyberattacks For example, a Russian espionage crew that Anthropic tracks as GTG-20006 – the state-sponsored cyber espionage arm of Russia’s Foreign Intelligence Service (SVR), also known as Midnight Blizzard, APT29, or Cozy Bear – increased the speed of its attacks by using AI to automate the entire kill chain.
Anthropic identified more than 20 organizations targeted in these attacks, including embassies, think tanks, defense-industrial companies, and government, defense, and intelligence agencies across Ukraine, Europe, the Middle East, Asia, and North Africa.
“We observed GTG-20006 operate through customized AI-driven workflows that automated much of their operations from development, infrastructure acquisition, phishing, persistence through command and control, to data exfiltration,” Anthropic said.
Meanwhile, “multiple clusters” linked to the data-theft-and-extortion gang ShinyHunters used Claude to scale their smash-and-grab operations.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.