Verified details show these actors used Claude to automate cyberattacks, conduct surveillance on dissidents, and generate large-scale influence campaigns across six continents.
The findings matter because they demonstrate how AI is collapsing the labor and skill gaps previously required for sophisticated offensive operations.
By delegating tasks like reconnaissance, exploit development, and data exfiltration to AI "agent swarms," lone operators can now execute multi-victim campaigns at machine speed.
Anthropic notes that this shift in unit economics makes previously marginal targets viable, essentially inverting the cost burden onto defenders who must now counter autonomous, iteratively improving malware.
Moving forward, Anthropic has implemented layered defenses, including new classifiers to detect adversarial extraction and "preserved thinking" to protect the model's internal reasoning from being stolen for unauthorized training.
The company is also restricting access to high-risk biological and cyber capabilities through trusted user programs.
These measures aim to protect the AI supply chain and global infrastructure as models become increasingly capable and the risk of misuse by persistent threat actors grows.