Anthropic has identified and halted a Russia-linked hacking operation that weaponized its Claude AI model in attacks against more than 20 government, intelligence, diplomatic and defense entities, according to a threat report released Thursday. The campaign, documented across the period from December 2025 through August 2026, represents one of the first detailed public accounts of state-sponsored actors systematically abusing frontier AI for cyber operations.

The company's analysis reveals that "state-backed hackers, criminal groups and individual hacktivists" have attempted to misuse its platform for cyber operations. Anthropic stated: "In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate."

Security researchers have largely welcomed the disclosure, though they note Anthropic stopped short of publishing aggregate statistics on the scale of detected misuse. The report distinguishes itself from competitor OpenAI's similar disclosures by offering granular technical breakdowns of multiple campaigns alongside indicators of compromise that security teams can operationalize.

Midnight Blizzard's drone espionage campaign

Anthropic attributed the primary campaign to Midnight Blizzard—also tracked as BlueBravo, APT29 and Cozy Bear—an operation Western intelligence agencies link to Russia's Foreign Intelligence Service (SVR). The group compromised hotel Wi-Fi infrastructure and manipulated DNS records to funnel travelers toward attacker-controlled servers, with Microsoft researchers connecting this activity to Storm-2945, a Midnight Blizzard sub-cluster.

The operation systematically targeted Ukrainian government officials, military personnel and diplomatic representatives, alongside organizations within the unmanned aerial vehicle supply chain. After penetrating email systems at two drone-component manufacturers, the attackers moved against a military drone producer and obtained a proprietary software development kit for drone vision technology.

The group then deployed Claude to reverse-engineer the vision system, "recovering its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product." According to Anthropic's analysis, "Military drone control and AI vision-related firmware appeared to be of particular interest."

AI accelerating the attack lifecycle

Beyond reverse-engineering, the hackers leveraged Claude to monitor whether security tools were detecting their malware. "When their implants were flagged by security products, the actor used Claude to systematically identify, modify and redeploy the detected artifacts," Anthropic reported.

This capability represents a fundamental shift in cyber conflict dynamics. As Anthropic noted: "The result of the above is that AI has inverted the cost back onto defenders. Previously, defenders might have been able to slow an attacker's operational tempo via the deployment of a new detection. Now, at least in theory, capable adversaries can 'close the loop,' bypassing traditional security detections faster than defenders can develop and deploy them."

The Five Eyes intelligence alliance underscored this risk in a June warning, stating that frontier AI models will likely "exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months."

Credential harvesting and vulnerability research

Beyond the Russian operation, Anthropic documented suspected ShinyHunters affiliates using AI to scan for credentials, enumerate unfamiliar infrastructure and exfiltrate victim data for extortion purposes. In one documented instance, an operator escalated from a compromised developer token to full administrative cloud access within approximately three hours.

A Chinese-speaking group, including two operators identified as undergraduates at a Hunan university, maintained an autonomous vulnerability research program centered on sustained attacks against a major security product, discovering multiple zero-day vulnerabilities in the process.

Anthropic also documented a French-speaking hacktivist deploying Claude against multiple European political parties, media outlets and think tanks, though the actor's specific motivations remained undisclosed.

Democratizing sophisticated cyber operations

Anthropic concluded that these cases—particularly the hacktivist's multi-target campaign—demonstrate how AI is narrowing the operational gap between nation-state actors and smaller threat groups by reducing the labor and technical expertise required to execute complex campaigns. The company emphasized, however, that AI has not displaced conventional attack vectors; phishing, credential theft, exposed services and software vulnerabilities remain central to successful intrusions.

The threat report extended beyond cyber operations to encompass other malicious applications including influence campaigns, surveillance, scams, fraud, biological misuse, conventional weapons development and model distillation.

Anthropic stated: "We're publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society's defenders act to make them safer."

Industry accountability concerns

David Agranovich, former Russia director at the National Security Council who later founded Meta's threat-disruption team and currently works on adversarial security at Google, highlighted the report's significance in a social media commentary. He noted that AI is lowering barriers to entry for cyber operations and transferring capabilities historically reserved for state actors to groups lacking the resources to develop such tools independently.

Agranovich cautioned against framing the disclosure narrowly: "some press coverage is going to frame this report as 'Claude was used to [do bad thing]' without noting that the only reason we know is because Anthropic dug into this and disrupted it." He warned that "If we don't incentivize (or require) companies to share this stuff, they'll stop."

Source: The Record