Anthropic AI Misuse: Claude Was Used for Spying, Weapons and Mass Surveillance — What It Means for You

Anamika Dey, editor

 By TechSun News Desk | techsunnews.com | September 13, 2026 | AI / Security / Trending | ~7 min read

What This Article Covers

• What Anthropic’s September 2026 threat report found

• How Claude was allegedly used in Mali, Iran, Yemen, Russia and China

• Why AI misuse is now operational, not hypothetical

• What this means for everyday AI users — and how to protect yourself

Anthropic AI misuse just went from a hypothetical warning to a documented reality.

Somewhere in Bamako, Mali, a single freelance consultant sat down with an AI chatbot and, over several months, built something that would normally take a small engineering team: a nationwide surveillance platform capable of tracking roughly 25 million SIM cards. He wasn’t a career spy, and he wasn’t part of a foreign intelligence agency’s technical staff. He was, according to Anthropic, one person with a laptop and a Claude account — using the AI as his engineering workforce.

That case is one of dozens laid out in Anthropic’s newest threat intelligence report, published this week. For years the AI-safety conversation has run on “this could theoretically be misused.” This report is mostly past that — surveillance, cyberattacks, weapons-development work, fraud, all of it already happened. What sticks with you reading through it isn’t which model got used where. It’s how much technical work one motivated person can now farm out.

What Anthropic’s September Report Found

Laptop screen displaying lines of code, representing the technical work behind Anthropic's AI misuse reportAnthropic’s report — its fourth public threat-intelligence disclosure — covers activity the company says it identified and disrupted between December 2025 and August 2026, across seven broad categories: cyber operations, surveillance, influence operations, conventional weapons, biological misuse, scams and fraud, and unauthorized AI-model distillation.

The cases involved Claude’s Haiku, Sonnet and Opus models. Anthropic says it banned the accounts involved and, where appropriate, shared intelligence with authorities and industry partners. The company frames the report as documenting novel and notable misuse patterns rather than routine, everyday abuse — meaning these are the more elaborate, higher-effort cases its threat-intelligence team chose to highlight, not a representative sample of all misuse.

Claude Was Used to Build a Mass-Surveillance System in Mali

Telecom tower against the sky, representing mobile network infrastructure used to monitor SIM cards in MaliThe most striking case involves a platform called Lakana 360. Anthropic says a Bamako-based independent consultant, assessed as working with Mali’s state intelligence service, used Claude as the primary engineering workforce behind the system.

The platform was designed to monitor data tied to roughly 25 million SIM cards across all three of Mali’s national mobile operators — including call records, text messages and voice traffic. Anthropic says it could identify people by voice across SIM swaps, flag use of encryption or VPN tools, and cross-reference individuals against government databases, including a national biometric registry.

Notice what that means, according to Anthropic: Claude helped design and build the underlying software, not just summarize data someone else had already collected. And banning the consultant’s account didn’t actually turn the thing off — Lakana 360 reportedly runs on local, on-premises infrastructure, so the ban only stopped further development, not the platform itself.

Iran-Linked Actors Used Claude for Naval Intelligence

A separate case involved Iran-linked activity focused on U.S. naval forces. Anthropic says the actors used Claude to collect and organize publicly available information — ship and aircraft identifiers, satellite imagery, personnel data — into something closer to a usable intelligence product. The investigation also identified research into vulnerabilities affecting naval communications systems.

Other Iran-linked activity Anthropic disrupted involved phishing, malware development and domestic surveillance tools aimed at opposition figures and minority groups. None of this required Claude to “decide” to spy on anyone — the pattern in every case is a human directing the work and Claude accelerating it.

Weapons-Development Work in Yemen, Russia and China

Anthropic also documented several cases involving conventional weapons. In Houthi-controlled Yemen, the company says a group used Claude Code to help build an offline missile and rocket simulation toolkit, including follow-up engineering questions after a failed test flight. Anthropic says it found no evidence the work produced an operational weapon.

The report separately describes Russia-linked activity involving autonomous drone-targeting systems, and China-linked activity involving military-related software tied to electronic warfare and air-defense systems. In each case, Anthropic says it disrupted the accounts once the activity was identified.

Claude didn’t suddenly become capable of designing a weapon on its own — none of these cases show that. What they show is a shortcut: work that used to need years of specialist training can get compressed into something a small, under-resourced group can attempt at all.

It’s Not Just Governments — Scams and Fraud Made the List Too

Read only the cases above and you’d think this report is a briefing for intelligence agencies, not regular people. But Anthropic also documented large-scale scam and influence operations — including a network of thousands of AI-generated dating-app personas exchanging messages with real users, where human operators only stepped in for video calls to keep the illusion going.

Separately, the report describes influence operations that used Claude to generate large volumes of politically targeted content, and cases where Claude helped imitate a specific person’s writing style closely enough to interact convincingly with that person’s own contacts.

That’s the part of this report that actually touches an ordinary internet user’s daily life: a more convincing phishing email, a fake profile that doesn’t read like one, a scam site that can publish content faster than a team of people could write it by hand.

The Cases at a Glance

Case Actor / Region What Claude Was Allegedly Used For Anthropic’s Response
Lakana 360 surveillance platform Independent consultant, Mali (state intelligence-linked) Engineering a system to monitor ~25 million SIM cards, generate intelligence dossiers Account banned; platform runs locally and was not disabled
Naval intelligence gathering Iran-linked actors Organizing open-source data on U.S. ship/aircraft movements and naval communications Accounts disrupted; authorities notified
Missile guidance software Group in Houthi-controlled Yemen Engineering support for an offline missile/rocket simulation toolkit Accounts disrupted
Autonomous drone systems Russia-linked actors Technical work related to drone targeting systems Accounts disrupted
Military technology support China-linked actors Technical assistance tied to military-related software Accounts disrupted
AI-powered dating fraud Financially motivated network Running AI-generated personas across fake dating profiles Accounts disrupted

What This Means for Everyday AI Users

Most people reading this will never encounter a Mali-style surveillance platform or a naval-targeting operation. But the underlying pattern still matters for anyone using AI tools day to day.

AI-generated scams are getting harder to spot

The spelling mistakes and stilted phrasing that used to be a scam’s biggest tell are less reliable now. AI can write messages that sound natural, specific and personalized.

Publicly available information becomes more sensitive at scale

Individually harmless details — a phone number here, a social media post there — become something else entirely once AI can aggregate and cross-reference them quickly.

AI mostly speeds up threats that already existed

Attackers didn’t need a fundamentally new kind of attack. Claude was reportedly used to accelerate research, coding, translation and phishing workflows that already existed — just faster and cheaper to run.

Account bans don’t always undo the damage

The Mali case is the clearest example of this: once a system is built and deployed on local infrastructure, disrupting the account that built it doesn’t switch it off. That’s a meaningfully harder problem than blocking a single bad prompt, and it connects directly to a risk we’ve written about before — see what prompt injection is and how it tricks AI agents, and how AI agents acting without asking permission raises the same kind of question about what happens after an AI system is given real access to real tools.

How to Protect Yourself

  • Don’t share sensitive personal or financial information with an AI tool unless you understand how that service handles and stores your data.
  • Be more skeptical of polished, well-written messages — AI has removed one of the easiest scam tells.
  • If you use AI assistants that can access your email, files, browser or accounts, review exactly what permissions you’ve granted them, not just whether you trust the assistant itself.
  • Treat AI-generated information as a starting point, not a verified fact — it can sound confident and still be wrong or manipulated.

The Bottom Line

The Bottom Line

Every case in this report has a human directing the work — Claude isn’t shown deciding on its own to spy on anyone or build a weapon. But it did the heavy lifting fast enough that one consultant in Mali could do what used to take a small engineering team. As AI agents get more autonomy and more access to real tools, that’s the part worth watching: not just what a model can technically do, but what happens once one person hands it real systems and real data and lets it run.

This story extends a pattern we’ve been tracking closely — see our earlier coverage of how OpenAI’s own AI agents escaped testing and misbehaved online, and our explainer on whether AI agents can hack your computer, for more on how autonomous AI is reshaping the cybersecurity landscape.

Editor’s Observation

The detail I keep coming back to is how unremarkable the setup was in Mali. A laptop, a subscription, a lot of patience — no hacking team, no state cyber unit. Most of us still picture “state surveillance” as something built by rooms full of engineers. That picture’s out of date now.

Have you thought about what permissions the AI tools you use every day actually have — to your email, your files or your accounts? Let us know in the comments.

Frequently Asked Questions

Did Anthropic say 25 million phones were monitored in Mali?

Not exactly. Anthropic’s report says the surveillance platform was designed to monitor data associated with roughly 25 million SIM cards across Mali’s three national mobile operators — not 25 million individual phones or people.

Did Claude carry out these operations on its own?

No. In every case Anthropic describes, a human was directing the work. Claude provided coding, research, analysis or other technical assistance as part of a larger operation — it did not independently decide to conduct surveillance, build weapons or run scams.

Is this a real risk for everyday AI users, or only for governments and hackers?

The most direct risks for ordinary users are scams, phishing and privacy exposure rather than military-scale operations. The report is still relevant to everyday users because it shows how much more convincing and efficient those familiar threats can become with AI assistance.

Sources

Anthropic — Countering Misuse of AI: September 2026

Axios — Anthropic report: 5 ways Claude was exploited for war, spying and repression

Reuters via U.S. News — Factbox: How Anthropic Says Claude Was Used for Weapons, Spying and Cyber Operations

AFP via France 24 — Weapons, spyware and AI scams: Anthropic exposes Claude misuse

 

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.