China used Claude AI to target 50 organisations, track Uyghurs and develop military systems: Here’s what we found in Anthropic’s investigative report 

· OpIndia

On Thursday, 10th September, the parent company of Claude AI, Anthropic, published a new investigative report [pdf] detailing how threat actors used its Claude artificial intelligence models for cyber operations, surveillance, weapons development, scams and other harmful activities. Titled “Detecting and countering misuse of AI: September 2026”, the report covers activity that Anthropic said it identified and disrupted between December 2025 and August 2026.

Visit milkshakeslot.lat for more information.

Anthropic said its Threat Intelligence team identified the operations through its monitoring and investigations into real-world misuse of Claude.

How Anthropic caught China-linked misuse of Claude

Anthropic investigated a sustained espionage operation, conducted by Chinese-speaking operators likely residing in Changsha in China’s Hunan province. 

The investigation identified two operators as undergraduate students at a Chinese university in Hunan who were studying in a School of Computer & Communication Engineering. One of them had previously interned at Chinese security company Sangfor and was interviewing for an offensive cyber operations position at another Chinese security company, QiAnXin.

An excerpt from the report

Anthropic said the operators used Claude as the “engineering and orchestration layer” for a coordinated offensive operation. Their activities included attempts to break into production systems, reconnaissance of foreign government networks across the Middle East, Europe and Southeast Asia, vulnerability research against major endpoint-security products, malware development and the creation of an intelligence-collection platform.

The investigation found that the operators were running several workstreams at the same time. These shared tools, infrastructure and persistent records allowed the operators to maintain campaign information between sessions. Some collection and vulnerability research processes could continue even when the human operators were away.

The group targeted roughly 50 organisations across education, retail, energy, technology, healthcare, finance and manufacturing, along with government agencies. Anthropic said the group accessed an education-technology company and extracted hundreds of megabytes of student data, gained access to production systems at a retail company and retrieved citizen information from a Southeast Asian government agency.

The AI system was also used to support the operation after access was obtained. Anthropic said the actors used Claude to enumerate systems, move through networks using reused or exposed credentials, collect information and continue from one compromised host to another. At the same time, their broader intelligence workflows collected open-source information connected to military and government priorities.

The report said the operators’ hands-on activity was concentrated on victims inside China, even though their AI-enabled workflows targeted organisations globally. Anthropic eventually banned accounts linked to the group and created additional detections based on the behaviour it observed.

Anthropic also found that a religious-affairs intelligence collection unit in China that had previously involved multiple teams of analysts had been reduced to a single office using an AI assistant to produce thousands of investigations every month. The company said AI was also being used to process large amounts of social media data and identify people for further monitoring.

China used Claude to track and recruit Uyghurs in Syria

Another shocking China-linked case involved the surveillance and recruitment of Uyghurs and Uyghur armed formations in Syria. Anthropic said, “We identified a PRC government-aligned operation that used Claude to track, profile, and recruit Uyghurs and Uyghur armed formations in Syria. The armed targets were ethnic Uyghurs who had recently joined the newly formed Syrian Army, formations the PRC government designates as terrorists.”

An excerpt from the report

The company further said that the actor used Claude to identify people in Syria who might have access to the armed formations and then attempted to recruit them, including by offering money in exchange for information about the units. The actor also used Claude to locate Uyghur businesses and other points of interest in Syria.

The operation was part of a wider campaign that also monitored Uyghur diaspora journalists and involved preparing bids for surveillance platforms for government clients. Anthropic assessed with low confidence that the operator was a contractor working for PRC state security rather than a state security organ directly.

According to the report, the actor used Claude to turn material collected from more than 100 WhatsApp groups and dozens of Telegram channels into structured Chinese-language profiles. The profiles included information about individuals who might be vulnerable because of financial problems, family separation or ideological dissatisfaction. The actor also identified people with family members still in Xinjiang.

Anthropic said Claude was used to help with the recruitment effort in Syrian Arabic, including translating messages and acting as an “expert” to check the language, military terminology and psychology used in deceptive outreach. The actor also used Claude to prepare plans targeting Uyghur diaspora media. 

The model, however, refused several requests involving covert interrogation and large-scale fake-persona creation.

Religious leaders and Chinese diaspora targeted

China-based PRC government used Claude as a stand-in for a staffed analyst team, building Chinese-language dossiers targeting religious leaders and Chinese diaspora figures across Asia. 

The actors used Claude as a “stand-in for a staffed analyst team” to create Chinese-language dossiers. Anthropic said, “The targeting mapped precisely onto the priorities of China’s religious affairs and united front apparatus (the party-state bodies that manage religious affairs and coopt or pressure groups perceived to be a threat to religious unity).”

An excerpt from the report

The actors instructed Claude to prepare documents that appeared to be intended for official internal security offices, including “personnel research drafts”, investigative “clue reports” and daily “situational awareness” reports. These documents included information about targets’ activities related to China, scandals and “抓手 (zhuāshǒu)”, a term used by the United Front Work Department to describe exploitable leverage.

The targets included senior Catholic cardinals across Asia, the leadership of the Presbyterian Church in Taiwan, Tibetan Buddhist civil society groups and the Tibetan administration in exile, as well as Falun Gong and affiliated media.

In one case, a single operator managed four parallel workstreams. Claude was asked to process information in multiple languages and turn it into structured Chinese-language dossiers using fixed templates. Anthropic said this effectively turned work normally done by a team of analysts into a workflow operated by one person.

China-linked “stability maintenance” surveillance

Anthropic also disrupted a China-based campaign involving what it called “stability maintenance” surveillance and transnational repression. The company said three linked operations involved actors connected to municipal public and state security organisations.

The term “stability maintenance” or 维稳 is used by China’s party-state system for efforts aimed at suppressing unrest and dissent. In one case, an actor prepared an internal manual on how to use AI, including instructions for Claude to act as an intelligence analyst serving China’s national security apparatus.

An excerpt from the report

Anthropic said, “We believe this actor is associated with a municipal cyber police unit, which used Claude to run a domestic sentiment surveillance program.” Another was a police academy student who identified 10 private Chinese citizens as targets for what the security system called “control”. A local state security bureau used Claude to produce daily “situational awareness” briefings on overseas dissidents and civil society organisations.

The targets included petitioners, rights defenders, pro-democracy figures in Hong Kong, organisers of Tiananmen Square commemorations, Uyghur advocacy groups and Western human rights organisations. In one case, Claude was asked to prepare information about venues and routes connected to overseas protests.

Anthropic said the three operations shared the same broad mission: identifying people likely to file grievances, monitoring rights defenders and tracking people classified as “key persons”. The monitoring was extended to overseas dissidents and diaspora communities.

AI-powered public opinion and dissident monitoring

Another China-based operation used Claude as an automated “public opinion monitoring” and intelligence-analysis system. Anthropic said, “The actor directed Claude to produce government briefings (舆情简报, restricted briefings for officials) that catalogued dissidents, activists, ethnic minority and Chinese diaspora communities, and foreign media as threats to political stability.”

The actor instructed Claude to role-play as a “senior emergency public opinion analyst serving the government of the People’s Republic of China.” Claude then produced documents that scored information according to political sensitivity and rewrote critical reporting according to rules designed to reflect the PRC’s preferred terminology.

The system processed between 15 and more than 30 foreign news articles a day from platforms including Weibo, X, YouTube, Telegram and Facebook. The actor also instructed Claude to change terms such as “Taiwan government” to “Taiwan authorities” and to put scare quotes around phrases such as “human rights violations”.

Anthropic said some of the resulting documents went beyond analysis and recommended enforcement measures that could only be carried out by government agencies. The company assessed with medium confidence that the operation was conducted by a contractor working for government clients, likely connected to China’s state security, United Front or propaganda system.

Claude used in conventional weapons activity

Anthropic said it also detected and disrupted the use of Claude in conventional weapons development by China. The company said its investigators had found multiple actors using Claude to develop weapons-related software or support intelligence and procurement work connected to weapons programmes.

“Historically, this kind of work has been uncovered by governments, United Nations panels, and outside investigators,” Anthropic said, adding that a frontier AI company can identify some of this activity directly when users violate its policies.

Anti-torpedo system and undersea warfare

In another misuse of Claude in a China-based case, an actor used Claude to work on an anti-torpedo weapons system. Anthropic said the actor was pursuing three parallel tracks.

The first involved drafting a Chinese-language specification for an anti-torpedo fire-control system intended for approval by a Chinese defence manufacturer. The second involved preparing a Chinese-language technical proposal of more than 200 pages along with an executive presentation. Third, the actor used Claude to benchmark their own system against specific US anti-torpedo and anti-submarine programs based on publicly accessible information, the company said.

The report added that the actor then generated a Chinese-language briefing on US Navy systems, based on open-source reporting. The actor presented itself as an original equipment manufacturer in the US defence sector.

“We assess that the actor was associated with the Chinese defence industry,” Anthropic said in the report.

Anthropic assessed that the actor was associated with a Chinese defence-industry manufacturer seeking to prepare a weapons specification and acquisition proposal for the People’s Liberation Army Navy.

The actor repeatedly used Claude to refine the proposal and asked it to act as a hostile expert reviewer to identify weaknesses before producing another version. Anthropic said the model was also used to develop parts of the fire-control software and a testing matrix.

Electronic warfare and air-defence suppression

Anthropic also disrupted a China-based operation involving electronic warfare and air-defence suppression. The actor used Claude’s chat, coding and agentic tools to develop a Chinese-language software suite containing around 16 modules.

The system was developed over 12 versions and included software for radar detection and jamming, vulnerability analysis and targeting instructions. Anthropic said the software could analyse radars, surface-to-air missile sites, command posts and communications nodes, while assessing detection coverage and the effectiveness of jamming.

Anthropic identified that the actor was a China-based defence and military-industrial researcher and said, “Based on our investigation, we assess the actor is a China-based defence and military-industrial researcher. Account-level metadata and content flagged by our safeguards indicated the actor was linked to PRC research institutions, including the PLA Academy of Military Sciences.” 

The company banned the accounts and said the findings were incorporated into new safeguards.

Intelligence on directed-energy weapons

A separate China-based actor used Claude to collect open-source intelligence on advanced directed-energy weapons and their supply chains. The actor described themselves as a defence intelligence writer and internal publication editor leading a three-person team.

Anthropic said, “Across dozens of sessions, the actor asked Claude about specific directed-energy weapons. These included inquiries about a vehicle-mounted high-power microwave weapon for countering drone swarms, which had been disclosed publicly days earlier. The actor also gathered information on the supply chain for procuring components that generate high-power microwave systems. The actor directed Claude to draft briefings for restricted internal circulation to senior Chinese Communist Party (CCP), military, or state security leadership.”

The actor tried to identify a particular microwave-generating device and its supplier, with the stated purpose of reverse-engineering the weapon, developing countermeasures and comparing it with Chinese systems. 

Anthropic said Claude was also used to map supplier ownership and prepare a 23-page report on foreign high-power microwave programmes.

China-based dating apps and AI personas

The report also described a large-scale scam involving a China-based app studio. Anthropic said, “A China-based app studio used Claude to both build a network of over 20 dating apps and power the AI personas used to converse with users-despite advertising their service as fully human.”

Over two weeks in April 2026, Anthropic identified more than 4,700 distinct AI personas that interacted with at least 25,000 unique people. The company said real people were also mixed into the dating-app feeds to make the service appear authentic, while AI tools helped those workers respond to users.

Anthropic also provided an update on illicit AI distillation, referring back to its first disclosure published in February 2026. “Since we published our first disclosure in February, we have identified and disrupted additional distillation attacks against Claude from seven labs based in China,” the company said. According to Anthropic, all seven attacks targeted generally available Claude models. 

Read full story at source