Key Takeaways
- Anthropic successfully intercepted and prevented misuse of Claude AI for biological weapons development, cyber intrusions, and influence operations from December 2025 through August 2026
- A notable incident included an attempt to leverage the AI for creating a grant proposal focused on gain-of-function experiments involving the chikungunya virus
- Bad actors ranged from nation-state threat groups and commercial spyware companies to cybercriminal organizations
- The company’s advanced Claude Fable and Mythos-class models remained largely untouched by these malicious activities, with only a single model distillation attempt recorded
- Enhanced security protocols have been implemented on latest-generation models, and threat intelligence has been distributed to government agencies and technology sector collaborators
On September 11, 2026, [[LINK_START_0]]Anthropic[[LINK_END_0]] released a comprehensive threat intelligence assessment documenting malicious attempts to weaponize its artificial intelligence systems during an eight-month period.
The assessment examines Claude AI exploitation attempts spanning from December 2025 to August 2026, marking the company’s third disclosure of this nature since initiating regular transparency reporting in March 2025.
Dangerous Biological Research and Weapons Development
The most alarming incidents documented involved efforts to leverage Claude for biological weapons-related activities. The company identified five distinct case studies within this threat category.
One particularly concerning instance involved a user requesting assistance in drafting a research funding proposal for gain-of-function experiments targeting the chikungunya virus. Such experiments involve genetic modification of organisms to enhance or introduce new capabilities.
The described research sought to engineer the virus for increased transmissibility and improved immune system evasion. Chikungunya is a mosquito-borne pathogen known for causing debilitating joint pain and high fever in infected individuals.
While Anthropic acknowledged that such research might have legitimate vaccine development applications, the company noted the dual-use nature that could enable creation of more dangerous pathogens.
According to the assessment, earlier-generation models like Claude Opus 4 and Claude Sonnet 4.5 lacked sufficient capability to provide meaningful assistance in advanced biological research applications. However, recognizing the enhanced capabilities of newer systems, the company has implemented more stringent protective measures.
Cyber Intrusions, Disinformation and Financial Fraud
The intelligence report documented numerous cases involving malicious cyber operations and coordinated influence campaigns. Specific threat actors identified included the ShinyHunters hacking collective and research facilities based in China.
One sophisticated operation, allegedly connected to Russia’s Midnight Blizzard threat group, attempted to use Claude for developing an automated system capable of rewriting malicious code whenever security software detected it.
The company catalogued nine separate influence operations with origins in Russia, Iran, Turkey, and spanning the Gulf region, South Asia, Africa and Europe. These campaigns deployed hundreds of fabricated social media profiles to amplify coordinated political narratives.
Additional malicious use cases encompassed fraudulent dating applications, compromised hotel wireless network schemes, and surveillance infrastructure designed to monitor political opposition figures.
Notably, Claude Fable and Mythos-class models were not implicated in these incidents, with the sole exception being one unauthorized attempt to extract and replicate model capabilities.
Anthropic confirmed successful interdiction of all malicious activities detailed in the report. The organization indicated it has incorporated lessons learned into enhanced safety protocols and coordinated with government authorities and industry counterparts on threat intelligence sharing.
This disclosure follows closely after researcher Jacob Coxon’s departure from Anthropic amid expressed concerns about the artificial intelligence industry’s rapid advancement toward superintelligent systems without sufficient safety frameworks.
The company stated its objective in publishing the report is to enable other AI developers to identify comparable threats while providing policymakers with enhanced visibility into evolving risk landscapes.





