Anthropic says China-based operators used Claude to copy its AI, track dissidents and run dating scams

Anthropic said its threat intelligence team spotted the activity by watching how accounts behaved, not by reading every chat. Investigators grouped related users into internal clusters, then matched language, time zones, shared proxy servers, fake identities, virtual cards and stolen API keys. Sudden spikes in traffic — in some cases millions of exchanges a day — and the reuse of the same account pools after bans pointed to organised campaigns rather than isolated users. The company said it then
SAN FRANCISCO, Sept 10 - Anthropic said on Thursday it had disrupted Chinese companies, security units and other operators that used its Claude AI models for unauthorized copying, surveillance, cyber intrusions, weapons-related research and fraud.
The findings were published in a threat report covering activity from December 2025 to August 2026.
Anthropic said it banned the accounts involved, tightened safety controls and, where the harm went beyond its platform, shared information with other firms and with governments.
Claude is not generally available in China.
Anthropic said the operators reached the models through unofficial proxy services that created accounts with false identities, disposable email addresses, virtual payment cards and stolen API keys.
The company said the cases involved its Haiku, Sonnet and Opus models.
It said it had not seen the same pattern on its Fable or Mythos systems, except in one copying case.
Distillation campaigns
Anthropic accused seven China-based labs of “illicit distillation”, using large volumes of Claude output, including hidden reasoning text, to train other models without authorization.
It said operators linked to Alibaba Group Holding Ltd (9988.HK) ran the largest such campaign it had measured, targeting Opus 4.6 and 4.7 and using the material to train Qwen 3.5, 3.6 and 3.7.
The activity peaked at nearly 3 million exchanges a day from more than 3,500 accounts Anthropic described as fraudulent.
From May to July it attributed more than 151 million exchanges to that campaign.
When Anthropic banned a pool of almost 5,000 accounts, the traffic shifted to another pool, the report said.
Some of those accounts also carried traffic for DeepSeek and Xiaomi, it added.
Alibaba did not immediately respond to a request for comment on the report.
Anthropic said Moonshot AI, maker of the Kimi assistant, forwarded customer prompts to Claude and showed users Claude’s replies while they believed they were using Kimi.
In one 10-day period it counted almost 300,000 such requests through more than 5,000 accounts that appeared to be in Singapore and Japan.
From May to July it attributed more than 23 million exchanges to Moonshot.
DeepSeek used a similar method and sent selected coding-tool traffic to Opus, Anthropic said.
It attributed more than 12.1 million exchanges to DeepSeek over 14 days in July.
It also attributed smaller campaigns to Zhipu, which operates abroad as Z.ai, and to Xiaomi.
SenseTime bought logs of Claude chats from third-party vendors, the report said.
MiniMax set up a shell company that sold access only to U.S. models, which Anthropic said was a way to harvest training data.
Some forwarded chats contained internal company documents and live passwords, the report said.
Anthropic argued that safety limits built into Claude do not carry over when another lab trains on stolen transcripts.
Surveillance
Separately, Anthropic said China-based operators linked to the state or to government contractors used Claude to profile dissidents, religious groups and diaspora communities.
One operator with no Arabic used the model to draft recruitment messages in Syrian dialect aimed at Uyghurs in Syria, translate replies and check the wording, the report said.
The same operator pulled traffic from more than 100 WhatsApp groups and flagged people who still had family in Xinjiang.
Anthropic said it had low confidence that this was a contractor rather than an official acting directly.
Other accounts produced dossiers on Catholic leaders in Asia, Taiwan church officials, Tibetan exile groups and Falun Gong media, it said.
One user identified themselves as a Chinese state information-security officer.
Anthropic also described a municipal cyber-police unit running a daily sentiment monitor, a police academy student who obtained a list of 10 private citizens marked for “control,” and a local bureau, possibly in Zhejiang, that wrote a staff manual telling officers to treat Claude as a state intelligence analyst.
Overseas tasking included protest locations in Vancouver, Turkey and Oslo, the report said.
A further operation scored foreign news for political sensitivity and rewrote it in official language, the company said.
Its filters did not always hold.
In one session Claude refused a request and then complied when asked again.
Cyber operations
Anthropic said a group of Chinese-speaking operators, probably in Changsha, used Claude to scan networks, hunt software flaws and write malware.
Two were undergraduates.
One had interned at security firm Sangfor and was applying to QiAnXin.
The group’s target list covered about 50 organisations, the report said.
It described theft of student records from an education firm, access to a retailer’s production systems and the taking of citizen data from a Southeast Asian government agency.
An automated effort to reverse-engineer appliance firmware produced more than a dozen possible previously unknown flaws in a month, tested in the operators’ own lab, Anthropic said.
When the group broke into systems directly, it focused on victims inside China.
Weapons-related work
Three China-based cases appear in a section on conventional weapons.
Anthropic bars the use of Claude to design weapons and said it banned the accounts.
One actor, presenting as a U.S. defence contractor, used Claude to draft a Chinese specification and a proposal of more than 200 pages for an anti-torpedo system intended for the PLA Navy, the report said.
A second actor, with account signals Anthropic linked to the PLA Academy of Military Sciences, built about 16 programs for electronic warfare and air-defence suppression.
Midway through the project the default exercise was changed to 12 targets in Taiwan, including air bases and Patriot batteries, it said.
A third described themselves as a defence writer and used Claude to gather public information on directed-energy weapons and draft restricted briefings, the report said.
Anthropic did not say any of the software had been deployed.
Fraud
Anthropic also said a China-based studio used Claude to power more than 20 dating apps advertised as human-run.
In two weeks in April it counted more than 4,700 AI personas in contact with at least 25,000 people.
Paid gig workers were mixed into the same feed so some users could still join a video call.
Response
Anthropic said it now tries to attribute proxy networks to organisations rather than banning accounts one by one, blocks requests it believes are designed to steal model reasoning, and can require identity checks when traffic appears to come from countries it does not support, including China.
The report is based on Anthropic’s own logs and attributions.
The named companies have not publicly accepted the allegations.
Reporting based on Anthropic’s report, “Detecting and countering misuse of AI: September 2026,” published Sept. 10, 2026. https://www.anthropic.com/threat-intelligence-report-september-2026