China for surveillance, Russia for weapons… How Claude was misused [Claude AI Abuse Report ③]

Photo of author

By Global Team

Key points

▶ Anthropic’s report documents 10 cases involving surveillance and six involving conventional weapons.

▶ Surveillance cases involved state-linked groups in China, Iran and West Africa, as well as private surveillance companies. The weapons-related cases involved China (three), Russia (two) and Yemen (one).

▶ In China, a guide to using Claude for surveillance was compiled as an internal manual. Investigators looked into the locations and routes of overseas gatherings, including a pro-democracy march in Vancouver and a Uyghur event in Türkiye.

▶ In Yemen, Claude was used to develop guidance, navigation and control software for a guided rocket, which was test-fired. The test appears to have failed, and the cause was analyzed with Claude again a few hours later.

▶ A Russian team developed swarms of FPV suicide drones capable of attacking without human intervention. “People” were among the target categories in the onboard model, which was designed to be able to issue detonation commands.

Anthropic released its 154-page report, “Detecting and Responding to AI Misuse, September 2026,” on the 10th (local time). The document details cases in which its AI, Claude, was used for malicious purposes. (Photo: Anthropic)
Anthropic released its 154-page report, “Detecting and Responding to AI Misuse, September 2026,” on the 10th (local time). The document details cases in which its AI, Claude, was used for malicious purposes. (Photo: Anthropic)

[Editor’s note] The misuse of AI is no longer just a possibility. Real-world cases have emerged involving hacking, espionage, opinion manipulation, surveillance, weapons and biological research. A 154-page report released by Anthropic shows how AI is changing the speed and scale of existing threats. Based on the report, Solution News examines how AI is being used as a tool for crime and state operations.

AI was even taking over work previously done by surveillance personnel.

Surveillance cases uncovered by Anthropic between January and July this year involved government agencies, government-linked groups and private surveillance companies. Claude was not just used to find information. It was used to build surveillance systems, analyze large volumes of data, identify targets and prepare reports.

In one case in China, a state security agency created an internal manual on how to use Claude. Anthropic said, “AI is now being used to replace engineering personnel.”

◆ Mali’s surveillance network covering 25 million SIM cards

The largest case came from Mali in West Africa. The report assigned it code GTG-50027.

An individual believed to be an independent consultant working in Bamako developed a surveillance platform called Lakana 360 for Mali’s National Security Agency (ANSE). It was designed to collect call records, text messages and voice calls from all three mobile carriers in Mali, covering about 25 million SIM cards.

Legal safeguards were also changed during development. One feature let an operator enter a phone number and have the AI generate an intelligence report on that number. At the operator’s request, the warrant-verification step for this feature was removed. Controls were disabled by default, and information was set to be retained indefinitely.

The system was designed to keep tracking people even after they changed SIM cards. It could identify users by their voice characteristics and flag those using encrypted communications or VPNs. It also included features to infer movements suspected to involve secret meetings and cross-reference them against the national biometric registry.

Anthropic blocked the account, but the surveillance network did not stop operating. Lakana 360 ran on local servers using its own AI model. Anthropic said blocking the account prevented further development but could not affect a system that had already been deployed.

◆ Iran’s central surveillance system, “Arman”

In Iran, Anthropic uncovered a case in which two separate organizations used the same centralized surveillance system. The report assigned it code GTG-34007. Anthropic blocked 16 related accounts.

The two organizations did not share code or personnel, but the information they collected flowed into a central system called Arman. Files on targets included national identification numbers, beliefs, criminal records and social media accounts. They also had fields for recording what action should be taken against each target.

One organization claimed to have surveilled 6,388 Iranians. The other actually distributed a malicious Firefox extension disguised as a prayer-time notification program, using it to collect social media users’ identifying information on a large scale.

Anthropic also acknowledged the limits of its safeguards in this case. Claude refused some explicit requests for profiling and propaganda, but failed to block many requests to create surveillance software.

A private surveillance company was also involved. The report assigned it code GTG-54009. Anthropic said a company called S2T Unlocking Cyberspace built a system to locate social media users in Iran and the Persian Gulf region and classify them by their views. It also produced Arabic-language intelligence documents formatted as government reports.

However, it was not confirmed whether the system was actually used for surveillance. Anthropic said it blocked the accounts at an early stage and found no evidence that later-stage features had been used against real targets.

◆ An AI manual for China’s security agencies

In China, signs emerged that AI had become part of the day-to-day work of state security agencies. The report assigned the case code GTG-14021.

Individuals from local Chinese public security and state security agencies used Claude for so-called “stability maintenance” work. They prepared daily “situational awareness” reports and compiled the process into a manual on using AI. The manual also included prompts instructing Claude to act as an intelligence analyst for a national security agency.

There was also an attempt to bypass safeguards. Claude initially refused a request to prepare a weekly “stability maintenance” report. But after the user repeated the instruction, it identified 10 Chinese people as targets for “control” and suggested ways to prevent them from filing complaints or to summon them for questioning. The recommendations also included closely monitoring their movements and communications.

Surveillance targets extended beyond China. The user investigated the gathering points, route and endpoint of a pro-democracy march in Vancouver. Other targets included a Uyghur cultural event in Türkiye and a screening event hosted by the Oslo Freedom Forum. Anthropic viewed this as the collection of field intelligence ahead of actual operations.

◆ Recruiting Uyghurs in Syria

Another case involved using Claude to surveil and recruit Uyghurs in Syria. The report assigned it code GTG-14010.

The group used Claude to organize information collected from more than 100 WhatsApp groups and dozens of Telegram channels. It identified details that could be used for recruitment, including individuals’ personal relationships, financial difficulties and family problems. It also sought out people whose families remained in Xinjiang.

The group tried to approach some people directly and recruit them as informants. Targets included Uyghur militants who had joined the newly formed Syrian army, as well as people who could gain access to them. In exchange for payment, the group also sought information about the units to which they belonged.

The operator did not speak Arabic. Instead, Claude wrote outreach messages in the local Syrian dialect and translated the recipients’ replies in real time. The operator also used Claude to check whether the dialect and military terminology sounded natural and whether the messages were appropriate to the situation.

Anthropic concluded that Claude allowed recruitment efforts to continue for days without the need for staff fluent in the local language. However, the group was not confirmed to be a Chinese state security agency. Anthropic assessed, with low confidence, that it might have been an outside contractor working on behalf of one.

◆ Yemen’s guided rocket test-firing

AI misuse extended beyond surveillance to weapons development. Anthropic disclosed six cases involving conventional weapons in this report: three in China, two in Russia and one in Yemen.

The most detailed case came from Yemen. The report assigned it code GTG-87001. A group in northern Yemen was developing several types of missiles at once, including guided rockets, multistage ballistic missiles with a targeted range of more than 2,000 kilometers, and hypersonic glide vehicles.

The group used Claude Code to develop guidance, navigation and control (GNC) software to steer and stabilize the vehicles. It ran several Claude instances at the same time, assigning one to write code, another to conduct research and a third to review the code.

Development went as far as a live test. The group fired a guided rocket, and the test appears to have failed. A few hours later, it used Claude again to analyze the cause of the failure.

Anthropic found no evidence that a fully operational weapon had been completed. It did, however, confirm that before the account was blocked, the group had already created offline simulation tools that did not rely on Claude.

◆ Russian autonomous suicide drones

In Russia, drones designed to attack without human intervention came to light. The report assigned the case code GTG-27005.

The group, which Anthropic believed to be a small team of freelance developers, was building a system to operate swarms of FPV suicide drones. The project was called “DronDoc” or “Serafim.”

Claude was used to create software that let the drones share information and keep the swarm moving even if some aircraft malfunctioned. The team also developed a terminal-guidance function that used cameras to steer the drones toward targets.

The most notable feature was how attack decisions were made. The model onboard the drones was designed to select targets itself, with “people” included among the target categories. It was also designed to let the model issue detonation commands without human intervention.

Training used Ukrainian combat footage collected online. Targets were classified as “enemy” or “friendly,” with Russian equipment excluded from attack. Specific coordinates in Ukraine’s Donetsk region were repeatedly used as demonstration strike locations.

Anthropic did not, however, consider the team to be a Russian state agency. The group claimed to have received funding from the Russian Foundation for Advanced Research and the Defense Ministry, among others, but Anthropic said it could not verify those claims.

◆ Twelve targets selected in Taiwan

In China, Anthropic uncovered a case involving software developed for electronic warfare and the suppression of air defenses. The report assigned it code GTG-17002.

A Chinese developer used Claude to build a system made up of about 16 modules. The program analyzed opposing radar systems, surface-to-air missile sites, command centers and communications facilities, then ranked which targets should be neutralized first. It also analyzed the engagement ranges of Patriot- and THAAD-class air defense systems.

During development, the default simulation scenario was changed to include 12 targets in Taiwan. They included command bunkers, early-warning radar, Patriot and Tien Kung air defense batteries, major air bases and regional combat commands.

In two other cases in China, Claude was used to design a torpedo interception system and gather information on directed-energy weapons.

◆ Russian procurement to evade sanctions

In Russia, Claude was also used to procure dual-use goods. The report assigned the case code GTG-27006.

A procurement officer at a Moscow design bureau considered bringing German-made magnetometers into Russia through a Chinese company. Space-grade solar cell wafers and aviation oxygen equipment were also on the procurement list.

Claude was used to find intermediaries in mainland China and Hong Kong and draft requests for quotations in English, Chinese and Russian. The officer used it to prepare documents that concealed the identity of the actual buyer and considered procurement routes through multiple countries to hide the goods’ final destination.

An internal report described the approach as a way to evade European trade controls. It proposed routing products blocked from direct supply to Russia through third countries, describing them as “sanctions-neutral jurisdictions.”

Anthropic said similar tactics recurred across the weapons-related cases. Users divided tasks across multiple sessions to conceal the overall development objective and bypass safeguards and access restrictions. Anthropic said it has since introduced a new classifier to detect and block requests related to high-yield explosives and weapons development.