Anthropic blocked abusive Claude use
Anthropic said it blocked Claude from surveillance, fraud and weapons uses, while Unit 42 reported commercial AI attacks in Latin America.
Anthropic said it blocked attempts to use Claude for surveillance, fraud, cyber operations and weapons development, including cases tied to Iran, Russia and China. Separately, Unit 42 reported attacks using commercial AI tools against transportation and finance sectors in Latin America.
Anthropic said it blocked multiple attempts to misuse Claude for surveillance, fraud, cyber operations and weapons development, including cases tied to actors linked to Iran, Russia and China. The material also includes a Unit 42 report that found attackers using commercial AI tools against transportation and financial organizations in Latin America, with help from self-hosted NextChat to debug errors and expose AI-generated scripts.
What types of abuse did Anthropic identify?
Anthropic grouped the incidents into seven categories: cyber operations, foreign influence campaigns, surveillance architectures, fraud, biological misuse, conventional weapons development and model distillation. According to Anadolu Agency, the last category refers to attempts by rival developers to extract the system's underlying reasoning without authorization.
Reuters also reported that the company accused Chinese competitors of trying to break into its Claude models to extract capabilities. At the same time, it described a new category of actors who used the platform to develop software for conventional weapons, including armed drones, missiles and control and guidance systems, along with intelligence and procurement support tied to weapons programs in China, Russia and Yemen.
Bloomberg said Anthropic claimed that actors linked to Iran and Russia used Claude in attempts to develop military capabilities, including kamikaze drone swarms, missile navigation systems and biological weapons. AFP added that the 154-page report identified a small team of freelance developers in Russia that allegedly used Claude to create software intended to control autonomous kamikaze drones.
What did it say about surveillance and operations in the Middle East?
Anthropic said a group linked to Iran's government used Claude to support surveillance operations against the United States and to draft attack recommendations against U.S. naval forces in the region. Iran International expanded on that point, saying the company attributed Claude use for propaganda, internal surveillance and profiling of people in Israel and the Jewish diaspora to state-aligned Iranian accounts and others linked to Iran.
Axios reported that Anthropic identified actors linked to the governments of Mali, China and Iran using Claude models to automate surveillance operations. One cited case involved the development of a malicious Firefox extension designed to collect user identities on social networks and select surveillance targets.
The Print added that an account linked to S2T Unlocking Cyberspace, described by open source research as an Israeli-Singaporean intelligence provider, used Claude to build a platform that profiles the social media activity of users in Iran and the Persian Gulf.
What happened in Latin America?
Unit 42 at Palo Alto Networks said on X that it saw attackers using commercial AI tools to target transportation and financial systems in Latin America. Varutra identified two active campaigns, CL-CRI-1131 and CL-CRI-1163, aimed at organizations in transportation, government, water services and the financial sector in Mexico, Ecuador and Brazil.
According to that analysis, the attackers used commercial large language models to generate scripts, debug technical problems and speed up the post-exploitation phase. Varutra added that the exfiltration infrastructure hosted NextChat as an access layer to multiple AI models, and that the use of commercial AI made it possible to automate reconnaissance, payload generation and exfiltration scripting, reducing operation times and increasing the malware's ability to adapt.
The Hacker News said that, between December 2025 and August 2026, both cybercriminals and state-sponsored hacking groups used Claude to automate exploitation and data theft across multiple victims. The publication framed the finding as the model being integrated into the full attack chain, beyond tactical assistance.
BBC added that Anthropic not only blocked uses tied to cyber operations, surveillance, fraud and weapons development, but also prevented some scientists from using Claude in ways that could support biological weapons development. The company presented a map of abuse that brings together state actors, criminals, freelance developers and scientific staff.
Sources
- Anthropic says Iran-linked accounts used Claude for propaganda, US naval targetingiranintl.com· Iran International
- Anthropic afirma que Irán y Rusia usaron Claude para desarrollar armasbloomberg.com· BloombergUnverified URL
- Unit 42 on X: "We saw attackers using commercial AI tools..."x.com· Unit 42 on X
- Governments are turning to Claude to automate spyingaxios.com· AxiosUnverified URL
- Anthropic blocks possible attempt to use AI to make biological weaponsbbc.com· BBC
- EXPLAINER - Anthropic threat intelligence report: What to knowaa.com.tr· Anadolu Agency
- Weapons, spyware and AI scams: Anthropic exposes Claude misuseafp.com· AFP
- Attackers Use AI-Assisted Intrusions and Data Exfiltration to Target Latin American Organizationsvarutra.com· Varutra
- Anthropic's startling revelations on misuse of its AI models. From State-sponsored hackers to spy opstheprint.in· The Print
- Claude Used to Automate Exploitation and Data Theft Across Multiple Victimsthehackernews.com· The Hacker News
- Anthropic disrupts bioweapons research efforts, Russian hacking, Chinese Claude misusereuters.com· ReutersUnverified URL
- Irán utilizó la IA Claude para planificar posibles ataques contra Estados Unidos, según Anthropicecuavisa.com· EcuavisaUnverified URL



