The abuses the company described
In a new report, Anthropic said that over the past eight months it had disrupted several campaigns in which Claude was used in multi-agent setups performing large portions of operations, rather than for individual prompts. Examples included phishing, hijacking hotel Wi-Fi connections, attempts to intercept WhatsApp[2] and automatically modifying malicious code after security tools detected it. [1 · Reuters]
The company also reported attempts to use Claude for software for conventional weapons, guidance systems, procurement and intelligence, while some researchers tried to bypass restrictions on dual-use biological work. Anthropic banned the associated accounts. [1 · Reuters] [2 · Associated Press] [3 · The Guardian]
Sources
- Reuters — main findings of Anthropic’s report — September 10, 2026
- Associated Press — attempts to misuse Claude for biological tasks — September 10, 2026
- The Guardian — contents of Anthropic’s 154-page report — September 10, 2026
Expert commentary
Anthropic accused seven Chinese laboratories of extracting Claude’s capabilities. It estimated that operators linked to Alibaba conducted more than 151 million exchanges, while Moonshot and DeepSeek routed live user conversations through Claude. The named companies did not provide detailed responses to Reuters[1], so these findings remain Anthropic’s claims. [1 · Reuters]
the report’s value lies in describing a shift from one-off prompts to automated sequences of actions. But the developer is simultaneously the data source, investigator and party imposing sanctions; independent verification of attribution and the claimed scale is necessary for final conclusions. [1 · Reuters] [2 · Associated Press] [3 · The Guardian]