Claude hijacked for spying, weaponizing and scamming: what Anthropic's report says

The report came out yesterday, it is 154 pages long and it is signed by Anthropic. Seven areas are covered: cyberattacks, opinion manipulation, surveillance, scams, conventional weapons, biology and model theft. The sentence that opens the document sets the tone for the company: we disrupted every operation described here.

It's true. A company that tells you in detail how its own tools were used to spy, arm and scam people, you don't see that every day, and it deserves credit for it. The report also exists because it serves its business, I'll come back to that at the end. The immediate interest lies elsewhere: any other platform can now go looking for the same traces inside its own systems.

Two things stopped me. The first is a story about Chinese models serving Claude to their customers without telling them. The second is what the word disrupted means when the machine is already installed somewhere.

Kimi was answering you, and Claude was at the other end of the line

Moonshot, the company behind Kimi, did something simple to describe and hard to swallow. A customer asks Kimi a question. Moonshot doesn't answer with its own model: it sends the question to Anthropic, retrieves Claude's answer, and serves it to its customer, who thinks they spoke to Kimi.

Almost 300,000 requests over ten days, sent through a network of 5,380 fake accounts. Between May and July, the report counts more than 23 million. And the detail that changes everything: Moonshot kept those exchanges. That was the whole point. They store them, clean them up, and use them to train their own model. The customer, for their part, thought they were paying for an in-house model.

DeepSeek did the same thing, with filtering that says a lot. Over fourteen days in July, more than 12.1 million exchanges. Their system identified users who went through a development tool, the likes of Claude Code, and those users saw their question sent to Claude. An employee had his company's internal documentation analyzed while thinking he was using DeepSeek. A Russian operator sent data from an agency linked to their Ministry of Defense. Engineers who were building case-management software for a police station sent theirs. None of them knew about it.

There's quite a queue. Zhipu, which sells its models under the name Z.ai: 3.4 million exchanges in seventeen days and 273 fake accounts to get around the limits. Xiaomi: 400,000 requests on 1,500 accounts. Seven Chinese labs in all, and a category the report names without beating around the bush: the industrial theft of a model by a competitor, using fake identities and stolen bank cards to open the accounts.

The passage that should concern all of us is almost a footnote. The requests Xiaomi sent to Claude went through routing services that American and European users rely on every day to access different models. Inside them: names, contact addresses, company data, from hundreds of people, in a dozen languages.

The report adds a caveat and you have to read it in full: nothing indicates that data belonging to people in the United States was exposed. Translation for the rest of us Europeans: nobody says the opposite either. What is certain is that these services are not limited to any one continent.

Diagram of the cycle of a model theft campaign, taken from the report

The cycle of a theft campaign, as the report describes it. Thousands of fake accounts are created, the model is harassed to wring its reasoning out of it, everything is cleaned up, the competitor is trained. Figure taken from the report

And there's the rest of the haul. In the exchanges recovered by Moonshot, a user uploads video-surveillance images from Chengdu, hundreds of cameras, some of them in front of military sites, to find out whether the person being followed is behaving abnormally. An engineer sends the live credentials of several major Chinese companies. Both thought they were talking to Kimi.

One person to monitor 25 million SIM cards

In Mali, one platform is called Lakana 360. Its client is the National State Security Agency. Behind the screen, according to the report, there is a single Claude subscriber: an independent consultant, probably based in Bamako. He did the work that a team of engineers used to do before him, the design, the code, the plumbing. His platform listens in on the country's three mobile operators, around 25 million SIM cards. Calls, SMS, and voice.

Where it gets ugly: the request for a judicial warrant was removed, at the client's request, from the module that writes an intelligence note on any number. The file gets built without a judge and kept indefinitely. The platform recognizes a voice from one SIM card to another, which puts paid to the prepaid phone bought at the market. It spots those who go through a VPN, infers clandestine meetings from locations, and cross-references names with the national biometric database.

And here is the sentence that matters most in the whole report, in my opinion. The platform runs on site, with models installed locally, not at Anthropic. Closing the consultant's account stopped the software's development. Not the platform, which continues to run without them.

The rest of the section is cut from the same cloth. A religious intelligence unit in China, which used to mobilize several teams of analysts, now fits into a single office and produces thousands of investigations per month. In Iran, two units that share neither code nor personnel separately solved the same problems of a state surveillance system, which means that the tool is making its way into administrative practice. And an Israeli-Singaporean vendor, S2T, got caught in the middle of building a product that sorts users of Gulf social networks into social categories, writes its notes in Arabic in the style of an official report, and prepares 255 fake accounts for what comes next.

Diagram of the data collection funnel of a commercial surveillance operation

From the entire population down to the person being targeted. On the left, what the machine could see, on the right, what the rest of the setup made possible. The report stops at the dotted line, and it says so honestly. Figure taken from the report

A guided rocket written by three Claude Code instances

A cell in northern Yemen, three programs in parallel: a guided rocket with a phone's onboard computer, a ballistic missile designed for a range of more than 2,000 kilometers, and a family of missiles, one variant of which glides at high speed.

The guidance software, the one that stabilizes the craft in flight and makes it go where you want, was written by Claude Code in place of engineers. And the way of doing it is that of a project manager: one instance writes the code, a second does the research, a third reviews what the first produced. They do not type questions into a chat, they supervise a small team.

Diagram of the development chain of a guided craft

The development chain of a guided craft, and how far the machine carried each of the three programs. The first went as far as the real launch. Figure taken from the report

The next part is my favorite passage in the report, and I am not quite sure what to make of it. The cell fired a guided rocket for real, somewhere in Yemen. The shot missed. And in the hours that followed, they came back to ask the machine the question again to understand why.

The rest of the list is less amusing. Three cases in China, including swarms of drones tested in simulation and then loaded onto real maps, targeting software for electronic warfare, a torpedo interception program. Two cases in Russia, on the supply of dual-use equipment. And each time the same end to the paragraph: the accounts were closed, but the people involved already had enough to continue offline.

4,700 fake girlfriends, 25,000 people, two weeks

Let's come back down to something you may already have had in your hands. A Chinese studio, more than twenty dating apps, and a well-crafted lie: the service presented itself as entirely human. In two weeks in April, the report counts more than 4,700 profiles run by Claude that spoke to at least 25,000 people. 2.36 million messages.

The setup is almost elegant. Three fake profiles for one real one. The real ones are workers paid by the task, recruited by invitation, and they do what a model still does not know how to do: the video call, subscribing to your Instagram account, the little proof that the person exists. They are assisted too, a small model whispers three replies to them, they tap the best one, and the conversation continues.

Diagram of the three-sided setup of a network of fake dating apps

The whole setup. At the top, the profiles run by the machine, at the bottom, the humans paid by the task, and in the middle, a user who pays for coins to keep chatting. Figure taken from the report

The apps were also designed to pass Apple's and Google's review. A button that appears only during the store's review and switches off afterward. Different class names in more than twenty variants, to prevent cross-checking between apps. A payment that goes through a third-party processor, disconnectable from the server on the day of the inspection.

And the line I will not forget, in the few conversations that were reviewed: the user says that they are seriously ill, or in distress. The model saw the problem, its own reasoning flagged it, and it continued playing its character.

The rest of the catalog, more quickly

Nine influence operations, from the fake news site to the fake NGO that copies the identity of a real Swiss organization. One wrote testimonies intended to be read before the United Nations Human Rights Council, with a precise instruction: that the name of the commissioning state should never appear. Another compiled files on 18 European MPs and journalists.

On the IT side, a group linked to Russian intelligence infiltrated providers that supply the Wi-Fi of several hotels, diverted the traffic of passing customers, took their WhatsApp accounts too, and got hold of 300,000 national identity records plus the company register of a North African country. The detail that sends chills down your spine: when one of their programs was detected by an antivirus, agents modified it and rebuilt it all by themselves until it went unnoticed again. The report calls this a reversal of the cost, defense becomes more expensive than attack. I have no better formula.

And five biology cases, including a grant application to make the chikungunya virus more transmissible, submitted by a military institute, and a complete application concerning a cousin virus of smallpox, written in an hour. In this field, the report writes something we never hear: the scientists involved are not movie villains, they are doing research, and some of them do not know what their program is really for.

Concretely, what does it change for you

At home, nobody understands anything about electronics and everyone couldn't care less, so I'll sum it up.

The first thing to remember is that an AI application is not necessarily what it claims to be. You type into Kimi, your sentence can come out at a competitor without anyone telling you, and this happened on a very large scale for months. This does not mean that all Chinese services are dishonest, or that the others are clean. It means that a service that answers you well is not proof that it does what its name says. I wrote the same thing a few days ago about the photos on your phone, and who looks at them.

The second concerns a free offer. The report says that Xiaomi launched its model with a free trial, then extended it, and that the bulk of the looting began right when the period was ending. Free access that drags on isn't always generosity, sometimes it's data collection. That goes for an AI application just as it does for any online service.

And the third is the one that will decide whether all this remains a problem for the big players or becomes your problem. Ten years ago, setting up surveillance on 25 million phones required a state, a budget, and a team of engineers. Today it required a consultant, a subscription, and the time of someone working from home. The report doesn't say when this shift becomes a problem for you. I think it has already happened, and that the day a public service buys the same kind of tool, nobody will find it strange.

My take

I'm not going to pretend to be outraged. It's the company I use every day, I spend my days in Claude Code, and if its models weren't useful to people with nothing to hide, nobody would talk about them. I've already called it out here for the conversations it kept for thirty days, and I will do it again.

What bothers me is the mixing of genres. A report like this serves two purposes at once. It really does inform, and that's valuable: the names, the figures, the methods, everything is there, and it can be checked. And at the same time it sells a position, that of the provider explaining to governments that the models should remain with American providers rather than go to a competitor that copies them. The section on the looting is the best part of the report, it's also the only one that speaks directly to Anthropic's wallet.

So I take the report seriously and keep the calculator beside me. What I know is that closing accounts stopped neither the Malian platform nor the Yemenis' offline simulators. We can be glad that a giant in the sector is telling us what it sees, and ask ourselves at the same time who is watching the watcher. No company publishes 154 pages against its own interests.

What really worries me isn't in the table of contents. It's that the cost of surveillance and military engineering has collapsed, and that a report published after the fact can only observe it.

The long version is in English, it's free, and it reads like a catalog. Enjoy the read, and watch where your sentences go.

Join the conversation

You need an account to comment on this article. Creating one is free and takes under a minute.

  • The XMLTV file, free to download every day
  • Comment on articles and reply to other readers
  • Get an e-mail when an article you follow is updated

No comments yet.

Une erreur s'est produite. Cette application peut ne plus répondre jusqu'à ce qu'elle soit rechargée.Veuillez contacter l'auteur. Reload 🗙