Anthropic Reveals AI-driven Espionage Targeting Defense Sectors

Anthropic disclosed that Russia-linked intelligence services utilized its Claude model to reverse-engineer drone technology and evade security detections, marking a significant shift in cyber warfare capabilities.
Anthropic has reported the detection and disruption of a sophisticated cyber-espionage campaign attributed to Russian intelligence services. According to a threat report released Thursday, the company identified state-backed actors using its Claude artificial intelligence model to target over twenty government, diplomatic, and defense organizations. The activity, observed between late 2025 and mid-2026, involved the misuse of generative AI tools to facilitate intrusion, data exfiltration, and the circumvention of security controls. The company stated that it intervened to block these operations and shared relevant intelligence with authorities and industry partners.
The incident highlights a growing concern among security professionals regarding the weaponization of large language models. While similar disclosures from other AI providers have focused on broad misuse metrics, Anthropic’s report provides specific technical details, including indicators of compromise. Analysts note that this level of transparency allows defensive teams to better understand how adversaries are leveraging AI to accelerate their operational tempo. The case underscores the rapid evolution of cyber threats, where traditional security measures may struggle to keep pace with AI-assisted attack methods.
Targeting drone supply chain integrity
The report details how the suspected Russian group, linked by Western intelligence to the Foreign Intelligence Service, compromised hotel Wi-Fi networks to redirect travelers to malicious infrastructure. This initial access facilitated the theft of sensitive data from drone component manufacturers. Specifically, the actors obtained a proprietary software development kit for a drone vision system. Using Claude, they reverse-engineered the system to uncover its architecture, hardware dependencies, and supplier details, including information on an unannounced product. The focus on military drone control and AI vision firmware suggests a strategic interest in understanding and potentially countering advanced autonomous systems.
AI inverts defensive cost burdens
A critical finding in the report is the ability of the actors to use AI for adaptive evasion. When security products flagged the group’s malicious tools, they employed Claude to identify, modify, and redeploy the detected artifacts. This capability effectively shifts the burden of adaptation onto defenders. Previously, deploying new detections could slow an attacker’s progress, but now, capable adversaries can bypass these controls faster than defenders can deploy updates. This dynamic challenges the traditional security model, where the cost of detection was lower for defenders than the cost of evasion for attackers.
The Five Eyes intelligence alliance has warned that frontier AI models will fundamentally transform both offensive and defensive cyber capabilities within months, not years. The recent disclosures align with this prediction, demonstrating how AI can compress the timeline for complex cyber operations. In other cases mentioned in the report, criminal groups used AI to scan for credentials and map systems, achieving full administrative access in record time. These examples illustrate a broader trend of AI accelerating the entire lifecycle of cyber attacks, from initial reconnaissance to lateral movement and data exfiltration.
Diverse actors exploit model capabilities
Anthropic’s report also highlights misuse by other groups, including a cybercriminal organization suspected of being affiliated with ShinyHunters. This group used AI to steal data for extortion purposes. Additionally, a Chinese-speaking group, including university students, utilized Claude to maintain an autonomous vulnerability research program. They successfully identified zero-day vulnerabilities in a major security product. These cases demonstrate that the threat landscape is not limited to state actors; various groups, from criminal syndicates to academic researchers, are exploring the offensive potential of AI models. The company noted that it has strengthened its safeguards based on these observations.






