Key Highlights
- Between December 2025 and August 2026, Anthropic successfully intercepted and blocked malicious attempts to exploit Claude AI for developing biological weapons, launching cyberattacks, and orchestrating propaganda operations
- Among the incidents was a request seeking assistance with a grant proposal for gain-of-function experiments involving the chikungunya virus
- Malicious actors included state-backed hacking groups, surveillance software companies, and cybercriminals attempting to misuse Claude’s capabilities
- The advanced Claude Fable and Mythos-class models remained largely untouched, with only a single distillation attempt recorded
- The company has strengthened protective measures on its latest models and coordinated with government agencies and tech industry partners
On September 11, 2026, Anthropic released a comprehensive threat intelligence assessment documenting malicious exploitation attempts targeting its AI technology over an eight-month period.
The assessment examines Claude AI misuse incidents spanning from December 2025 through August 2026, marking the company’s third public disclosure of this nature since initially launching such reports in March 2025.
Dangerous Biological Research and Weapons Development
The most alarming incidents centered on efforts to leverage Claude for research connected to biological weapons development. The company identified and documented five distinct case studies within this threat category.
A particularly concerning incident involved a user requesting Claude’s assistance in drafting a grant submission for gain-of-function experiments targeting the chikungunya virus. Such research involves genetic manipulation of organisms to enhance or introduce new characteristics.
The planned experiments sought to engineer the virus for increased transmissibility and enhanced immune system evasion capabilities. Chikungunya is a mosquito-transmitted virus responsible for debilitating pain and high fever in infected individuals.
While acknowledging that this research category could potentially contribute to vaccine advancement, Anthropic emphasized the dual-use risk of making pathogens more lethal.
According to the company, earlier-generation models like Claude Opus 4 and Claude Sonnet 4.5 lacked sufficient capability to provide meaningful assistance with hazardous biological research. However, as newer models demonstrate increased capabilities, Anthropic has implemented more stringent protective controls.
Cyber Warfare, Disinformation Campaigns and Fraud Schemes
The assessment also documented numerous incidents involving cybercriminal activity and coordinated influence operations. Specific threat actors identified included the hacking collective ShinyHunters and research facilities based in China.
An operation linked to Russia’s Midnight Blizzard threat group reportedly attempted to use Claude for developing an automated system that would continuously rewrite malicious code each time security software detected it.
The company uncovered nine separate influence campaigns traced to Russia, Iran, Turkey, along with operations originating from the Gulf region, South Asia, Africa, and Europe. These campaigns deployed hundreds of fraudulent social media profiles to disseminate coordinated political narratives.
Additional misuse patterns included fraudulent dating applications, malicious hotel Wi-Fi networks, and surveillance platforms designed to monitor political dissidents.
With the exception of a single unauthorized model distillation attempt, none of the documented incidents involved Claude Fable or the Mythos-class model family.
Anthropic confirmed that every malicious activity detailed in the report was successfully prevented. The organization has leveraged these findings to enhance its protective systems and has coordinated intelligence sharing with government authorities and technology sector partners.
This disclosure follows closely after researcher Jacob Coxon’s departure from Anthropic, who publicly expressed concerns about the AI industry’s accelerated pursuit of superintelligence without sufficient safety protocols.
Anthropic stated its intention for the report to assist fellow AI developers in identifying comparable threats while providing policymakers with enhanced visibility into the evolving threat landscape.


