2 hrs ago
Anthropic Disrupts Alleged Russian and Chinese AI Campaigns
Anthropic makes an artificial-intelligence system called Claude.
It said some hackers and AI companies misused Claude in several campaigns.
One suspected Russian-linked group allegedly targeted Ukrainian officials and organizations.
The group used AI to help with phishing, stealing access to Wi-Fi and taking over WhatsApp accounts.
It also allegedly made malware change itself when security tools detected it.
Anthropic accused several Chinese companies of using Claude’s answers to help train or improve their own AI models.
Alibaba allegedly made more than 151 million exchanges with Claude using thousands of accounts.
Anthropic said people often supervised these operations while AI systems performed many of the tasks.
Anthropic said it disrupted several alleged malicious uses of Claude over the past eight months.
The company linked one campaign to a Russia-based group targeting Ukrainian government, military and diplomatic organizations.
Anthropic accused seven China-based labs, including Alibaba, Moonshot, DeepSeek and Xiaomi, of misusing Claude.
Alibaba allegedly generated more than 151 million Claude exchanges through over 3,500 fraudulent accounts between May and July 2026.
Anthropic said AI systems orchestrated much of the activity, including phishing, malware evasion and alleged model distillation.
- Who
- Anthropic, Chinese AI companies including Alibaba, Moonshot, DeepSeek and Xiaomi, and a suspected Russia-linked group associated with Midnight Blizzard.
- What
- Anthropic said it disrupted alleged AI-enabled cyberattacks and attempts to extract or replicate Claude’s capabilities.
- Where
- The alleged cyber campaign targeted Ukrainian government, military and diplomatic organizations; the model-related activity involved China-based labs and Anthropic’s Claude systems.
- When
- The alleged activity occurred over the eight months before Anthropic’s September 10 report; Alibaba activity cited by Anthropic occurred between May and July 2026.
- Why
- The alleged operators sought to conduct cyber espionage, evade malware defenses, and use Claude’s outputs to train or improve other AI models.
Anthropic’s allegations
Reported operators’ positions
Use of Claude for model training
Anthropic’s allegations
Anthropic alleged that Alibaba sought to extract Claude’s capabilities to improve its Qwen models, while Moonshot and DeepSeek allegedly routed live customer conversations through Claude for training data.
Reported operators’ positions
The supplied reports do not include responses from Alibaba, Moonshot, DeepSeek or Xiaomi, so their positions are not established.
AI-enabled cyber espionage
Anthropic’s allegations
Anthropic said a group whose methods resembled Russia-based Midnight Blizzard used AI throughout phishing, hotel Wi-Fi hijacking and WhatsApp-takeover operations against Ukrainian targets.
Reported operators’ positions
The supplied reports do not include a response from Midnight Blizzard or Russian authorities.
Role of artificial intelligence
Anthropic’s allegations
Anthropic said AI directly executed or orchestrated most of the reported operations, with humans often acting as overseers.
Reported operators’ positions
No alternative assessment of the extent of AI involvement was provided in the supplied reports.
Key facts
- Company reporting the disruptions
- Anthropic
- AI model targeted or misused
- Claude
- Chinese labs named
- Alibaba, Moonshot, DeepSeek and Xiaomi were among seven China-based labs Anthropic identified.
- Alibaba exchanges
- More than 151 million exchanges were attributed to Alibaba between May and July 2026.
- Accounts attributed to Alibaba
- More than 3,500 accounts were described by Anthropic as fraudulent.
- Peak daily activity
- The Alibaba-linked activity peaked at nearly 3 million exchanges per day.
- Russian-linked targets
- Ukrainian government, military and diplomatic targets.
Quotes
Anthropic
The artificial intelligence company that published the threat intelligence report
“A majority of the operations … were enabled by AI via direct execution or orchestration. The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing tasks”
theprint.in







