On September 11, 2026, Anthropic said it had detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic, and defense organizations. The findings are in a threat report covering activity between December 2025 and August 2026.
Plain version: spies used an AI assistant to help steal military drone software, mess with hotel Wi-Fi, and rewrite hacking tools after security products caught them. Anthropic says it shut the activity down, tightened its safeguards, and shared what it learned with authorities and industry partners.
The group Anthropic tied to Russia’s SVR
Anthropic said the activity lined up with Midnight Blizzard, also known as BlueBravo, APT29, and Cozy Bear. Western intelligence agencies have attributed that group to Russia’s Foreign Intelligence Service, the SVR.
The hackers compromised hotel Wi-Fi providers and changed DNS records so travelers got sent to attacker-controlled systems. Anthropic cited Microsoft’s investigation linking that activity to Storm-2945, a sub-cluster of Midnight Blizzard.
They repeatedly targeted members of the Ukrainian government, military, and diplomatic staff, plus companies in the drone supply chain.
How Claude was used on stolen drone technology
After getting into the mailboxes of two drone-component manufacturers, the spies targeted a military drone maker and stole a complete proprietary software development kit for a drone vision system.
Then they used Claude to reverse-engineer that vision system. Anthropic said they recovered its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product. Military drone control and AI vision-related firmware were of particular interest, the report said.
That is not a party trick. That is using an AI assistant to turn stolen files into a working map of how a military product is built, who supplies the parts, and what is coming next.
AI that rewrites malware when defenders catch it
The same crew used Claude to watch whether security products were detecting its hacking tools. When implants got flagged, the actor used Claude to systematically identify, modify, and redeploy the detected artifacts.
Anthropic put the problem in blunt terms. AI has inverted the cost back onto defenders. Used to be, a new detection could slow an attacker down. Now a capable adversary can close the loop and bypass those detections faster than defenders can write and ship them.
The Five Eyes intelligence alliance had warned in June that frontier AI models will likely exceed current industry expectations and fundamentally transform both offensive and defensive cyber capabilities. Their line was simple: the timeline is not years, it is months.
Criminals and smaller operators used Claude too
This was not only a nation-state story. Anthropic said it also saw state-backed hackers, criminal groups, and individual hacktivists trying to misuse its tools.
Suspected affiliates of the ShinyHunters cybercriminal group used AI to scan for credentials, map unfamiliar systems, and steal data for extortion. In one case, an operator went from a stolen developer token to full administrative access in a victim’s cloud environment in about three hours.
A Chinese-speaking group, including two operators identified as undergraduates at a Chinese university in Hunan, kept an autonomous vulnerability research program running. The centerpiece was sustained research against a major security product. They found several zero-day vulnerabilities in it.
A French-speaking hacktivist used Claude in attacks on several European political parties, media organizations, and think tanks. Anthropic did not describe that person’s specific motivations.
The company said these cases, especially the hacktivist’s multi-victim campaign, show AI is narrowing the gap between state-backed groups and smaller operators by cutting the labor and expertise needed to run complex campaigns.
It also said AI is not replacing the old playbook. Phishing, stolen credentials, exposed services, and software flaws are still how most successful hacks start.
What Anthropic put on the table, and what it held back
Security folks have largely applauded the report. Unlike similar reporting from rival OpenAI, Anthropic included in-depth analysis of several campaigns and abuse types, plus indicators of compromise that security teams can actually use.
What it did not share are broader figures on how much misuse it is detecting overall. That gap matters if you want to know whether this is a handful of ugly cases or a firehose.
Beyond cyber operations, the report also covered influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Anthropic said it is publishing the work because it believes it has a responsibility to disclose malicious misuse of its services, and that risks will rise as models get more capable unless developers and defenders make them safer.
David Agranovich, a former Russia director at the National Security Council who later founded Meta’s threat-disruption team and now works on adversarial security at Google, said the report shows AI is lowering the barrier to entry for cyber operations. It is handing what used to be state-grade capabilities to actors who could never have built them.
He also cautioned that some coverage will frame this as Claude being used to do a bad thing, without noting the only reason we know is because Anthropic dug in and disrupted it. His warning: if we do not incentivize or require companies to share this stuff, they will stop.
That last part is the one I care about for regular people. You cannot protect your shop, your town, or your family from a threat nobody will admit is happening.
What this means if you are not a spy agency
You do not need a government badge to take the right lessons from this. The spies still needed a stolen mailbox, a hotel network, a developer token, or an exposed service before Claude became useful. The AI made the second half of the job cheaper and faster.
- Stolen credentials are still the front door. A developer token turned into full cloud admin access in about three hours. Lock down tokens, rotate them, and treat them like house keys, not souvenirs.
- Hotel and public Wi-Fi is a real targeting path. If you travel for government, defense, or anything that looks like it, do not trust the lobby network with work logins.
- Detection is not a finish line anymore. If attackers can ask an AI to rewrite the tool you just caught, your security stack has to assume they will come back the same day with a new coat of paint.
- Small operators can now run bigger campaigns. Undergraduates and a single hacktivist used the same class of tool as a Russian intelligence crew. That gap is closing.
- Demand the disclosure. Anthropic published campaign details and indicators of compromise. More companies should. If they bury the abuse, you are the one left guessing.
I have been at this long enough to know a new tool does not invent crime. It just changes the price. Right now the price of complex hacking is dropping, and the people paying the difference are the defenders, the small businesses, and the outfits that cannot hire a 24-hour threat team. That is the part that should piss you off. Not the chatbot. The imbalance.
Primary Source: https://therecord.media/anthropic-russia-hackers-claude
