Anthropic has disrupted Russian and Chinese campaigns that tried to weaponize its Claude models, the company said, terminating the accounts involved and cutting off access to the API. The disclosure lands as frontier labs face a widening set of state-linked actors probing their systems for use in influence operations, cyber intrusion, and other malicious workflows.
The disruption follows a broader pattern Anthropic has been documenting through the year, in which foreign operators attempt to route commercial AI capabilities into offensive campaigns. The company has repeatedly published takedown notices tied to specific clusters of activity rather than aggregating them into a quarterly report, a cadence that keeps the disclosures close to the underlying investigations.
Anthropic did not name the specific operators publicly, but attributed the activity to Russia and China. Claude access for the accounts in question has been revoked, and the associated infrastructure flagged in the company's internal detection systems to prevent re-entry through new accounts.
Key facts
- 01Anthropic disrupted Russian and Chinese campaigns that attempted to abuse its Claude models, according to Reuters.
- 02The company terminated the accounts linked to the operations and cut off access to Claude.
- 03The disruption adds to a growing pattern of state-linked actors trying to use frontier AI models for influence and cyber operations.
The pattern echoes disclosures earlier in the month, when Anthropic said Chinese labs had conducted a 200-million-exchange distillation campaign against Claude, and when US authorities named six Chinese AI firms tied to an industrial-scale distillation effort against Western frontier models. The through-line is that Claude, like every leading commercial model, has become a target both for extraction of its capabilities and for direct misuse.
The mechanics of these campaigns typically fall into a few buckets. Some operators use frontier models to generate influence content at scale, tailoring narratives to specific regional audiences. Others use them as coding and reconnaissance aids for cyber operations, asking the model to draft phishing lures, obfuscate payloads, or walk through the mechanics of a specific exploit. Anthropic has described enforcement actions against variants of all of these use patterns.
For Anthropic, publishing the disruptions serves two purposes. It documents that the company's usage policies are being enforced with real consequences, which matters for enterprise customers and government contracts that require demonstrable trust-and-safety controls. It also gives peer labs, including OpenAI and Google, shared threat intelligence on which actors are probing which surfaces.
The harder question is whether disruption at the API layer is enough. State-linked operators can pivot to open-weight models that carry no terms-of-service enforcement, and the gap between closed frontier models and the best open-weight alternatives has narrowed considerably in the past year. A campaign shut down on Claude today can, in principle, restart on a locally hosted model tomorrow — one of the reasons Anthropic and its peers have argued publicly for compute-level and export-level policy tools rather than relying solely on account terminations.
Skeptics note that these takedown announcements are difficult to independently verify. Anthropic controls the evidence, defines the scope, and chooses what to publish. Without independent auditing, it is hard to know whether disclosed disruptions represent a small sample of a much larger problem or the majority of what the company actually catches. Anthropic has said it aims to expand its threat-intelligence publications over time; how much detail it releases, and how quickly, will determine how much weight outside researchers can put on them.
For the AI market, the steady drumbeat of state-linked misuse disclosures is becoming a permanent operating cost of running a frontier lab. Every commercial provider now needs a threat-intelligence function, a takedown workflow, and a public disclosure cadence — capabilities that did not exist as line items two years ago. Anthropic's willingness to publish these disruptions, even at the cost of highlighting that its models are being targeted, is a bet that transparency compounds into trust faster than silence compounds into doubt. So far, that bet has aligned with how enterprise buyers and governments are choosing which labs to work with.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




