Anthropic Disrupts Russian State-Linked Hackers Using Claude AI in Espionage Campaign
AI developer **Anthropic** has revealed it detected and disrupted a sophisticated cyber-espionage campaign leveraging its **Claude** AI tool. The campaign, attributed to a Russia-linked group, targeted over 20 government, intelligence, diplomatic, and defense organizations, highlighting the evolving landscape of AI misuse in cyber operations.
In a comprehensive threat report spanning December 2025 to August 2026, **Anthropic** detailed how state-backed hackers, criminal groups, and individual hacktivists attempted to weaponize its AI models.
"In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate," the company stated.
While the report has been praised by security experts for its in-depth analysis and inclusion of Indicators of Compromise (IOCs), it notably refrains from disclosing the broader scale of misuse detected.
### Midnight Blizzard Leverages AI for Espionage
**Anthropic** identified the primary state-backed actor as **Midnight Blizzard**, also known as **BlueBravo**, **APT29**, and **Cozy Bear**. This group, widely attributed to Russia's Foreign Intelligence Service (**SVR**), employed **Claude** in a series of targeted attacks.
The hackers were observed compromising hotel Wi-Fi providers and manipulating DNS records to redirect travelers to attacker-controlled infrastructure. **Anthropic** cited **Microsoft's** investigation, linking this activity to **Storm-2945**, a sub-cluster of **Midnight Blizzard**.
Crucially, the Russia-linked spies repeatedly targeted Ukrainian government, military, and diplomatic staff, as well as entities within the drone supply chain. After breaching the mailboxes of two drone-component manufacturers, they stole a proprietary software development kit for a drone vision system from a military drone maker.
### AI for Reverse Engineering and Evasion
**Claude** was then used to reverse-engineer the stolen drone vision system, allowing the attackers to recover its product architecture, hardware bill of materials, supplier dependencies, and details of an unannounced product. "Military drone control and AI vision-related firmware appeared to be of particular interest," the report highlighted.
Furthermore, the group leveraged AI to monitor the efficacy of their hacking tools against security products. When their implants were detected, they used **Claude** to systematically identify, modify, and redeploy the detected artifacts.
This capability, **Anthropic** warns, could dramatically shift the cost burden onto defenders. "Previously, defenders might have been able to slow an attackerβs operational tempo via the deployment of a new detection. Now, at least in theory, capable adversaries can βclose the loop,β bypassing traditional security detections faster than defenders can develop and deploy them."
This aligns with warnings from the **Five Eyes** intelligence alliance in June, which cautioned that frontier AI models would "exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months."
### Broader Misuse by Criminals and Hacktivists
Beyond state-sponsored activity, **Anthropic** also documented other malicious uses of **Claude**:
* **ShinyHunters** affiliates reportedly used AI to scan for credentials, map unfamiliar systems, and exfiltrate data for extortion. In one instance, an operator progressed from a stolen developer token to full administrative access in a victim's cloud environment within approximately three hours.
* A Chinese-speaking group, including two university undergraduates, maintained an "autonomous vulnerability research program" that discovered several zero-day vulnerabilities in a major security product.
* A French-speaking hacktivist utilized **Claude** in attacks against multiple European political parties, media organizations, and think tanks.
These cases, particularly the hacktivist's multi-victim campaign, demonstrate how AI is lowering the barrier to entry for complex cyber operations, reducing the labor and expertise traditionally required for such campaigns.
However, **Anthropic** emphasized that AI is not replacing traditional attack methods. Phishing, stolen credentials, exposed services, and software flaws remain central to successful hacks.
### A Call for Transparency and Responsibility
The report also touched on other malicious uses beyond cyber operations, including influence operations, surveillance, scams, fraud, and even biological misuse.
"Weβre publishing this work because we believe we have a responsibility to disclose malicious misuse of our services," **Anthropic** stated. "As models become increasingly capable, their risks will increase, unless AI developers and societyβs defenders act to make them safer."
**David Agranovich**, a former Russia director at the **National Security Council** and now at **Google**, underscored the report's significance. He noted that AI, much like the commercial spyware industry before it, is democratizing state-grade cyber capabilities for a broader range of actors.
**Agranovich** also cautioned against misinterpreting the report as a solely negative portrayal of **Claude**, emphasizing that the transparency is due to **Anthropic's** proactive detection and disruption efforts. "If we donβt incentivize (or require) companies to share this stuff, theyβll stop," he concluded, advocating for continued transparency in the AI industry.