Summary
- Anthropic says it disrupted malicious use of Claude linked to state-aligned and criminal activity between January and September.
- One assessed Russia-linked campaign used AI across phishing, malware adaptation, and other activity targeting Ukrainian organisations.
- The findings are Anthropic's attribution and threat-intelligence assessments rather than independently established attribution.
Anthropic says it has disrupted a series of malicious campaigns in which state-linked and criminal actors used its Claude models across multiple stages of cyber operations, including activity targeting Ukrainian government, military, and diplomatic organisations.
The company attributed one cluster of activity to tradecraft consistent with Midnight Blizzard, a Russia-linked espionage group also tracked under names including APT29. Anthropic said the actors used AI to support phishing, adapt malware, assist with account compromise, and work through other operational tasks.
Those conclusions remain Anthropic’s threat-intelligence assessments. The company has visibility into use of its own systems, but public reporting does not provide enough independent evidence to treat every attribution or operational detail as settled fact.
The broader pattern is nevertheless important because it shows AI being incorporated beyond isolated coding or translation tasks. Anthropic described campaigns in which human operators remained involved while models were used to accelerate or automate portions of reconnaissance, content creation, malware modification, and analysis.
That hybrid model is increasingly plausible for espionage operations. Offensive campaigns contain many repetitive steps that do not require a model to discover an entirely new exploitation technique. Drafting believable lures, translating text, analysing stolen data, adapting scripts, and troubleshooting tools can all consume operator time even when the underlying tactics are familiar.
Generative AI can reduce that friction. The resulting change may be less dramatic than the idea of a fully autonomous attacker, but it can still alter the economics of an operation by allowing the same team to work across more targets or iterate more rapidly.
Anthropic’s disclosure also included China-linked activity and attempts to extract capabilities from Claude through large-scale interaction with the models. The company’s findings therefore span both direct malicious use and efforts by outside organisations to appropriate or reproduce model behaviour.
For European security policy, the emerging issue is not simply whether AI creates novel attacks. It is whether existing state and criminal operations become cheaper, faster, and easier to scale while defenders face their own governance constraints around deploying autonomous systems.
Ukraine provides a particularly consequential environment for that shift. Cyber operations there have run alongside conventional military activity for years, affecting government, telecommunications, energy, logistics, and other systems. The use of AI to assist espionage does not replace established techniques, but it can become another layer within already mature operational programmes.
The disclosure also places model providers in an increasingly active security role. Companies such as Anthropic are not only software vendors: they can observe patterns of model use, terminate accounts, investigate suspicious interactions, and publish intelligence about activity occurring through their platforms.
That position creates an accountability problem of its own. Providers must distinguish legitimate security research from malicious use, decide when behaviour crosses an enforcement threshold, and determine how much supporting evidence can be disclosed without exposing detection methods or customer data.
Anthropic’s findings indicate that sophisticated actors are already experimenting with the practical advantages of large models rather than waiting for fully autonomous offensive systems. The immediate risk is therefore evolutionary rather than speculative: established espionage tradecraft is gaining another automation layer, while the companies supplying that layer become increasingly important sources of intelligence about how it is being used.





