Claude misuse has moved from theoretical concern to operational reality. Anthropic’s latest report on the abuse of its AI assistant catalogs a range of cases that reads like a security briefing for the current decade: a Russian state-backed hacking group using Claude for reconnaissance, a prolific cybercrime crew relying on it across whole extortion campaigns, political disinformation operations in Kenya and Bangladesh, and users attempting to develop bioweapons. The company presents these as examples of its safety systems working. The broader picture, though, is less comforting. Claude misuse is already everywhere, and no single company can plausibly claim to see all of it.
Claude Misuse Now Spans State Hacking, Disinformation, and Bioweapon Research
Anthropic’s report is built around case studies that demonstrate how a commercially available AI assistant can be pulled into nearly every category of malicious online activity. The most alarming examples are not unsophisticated experiments. They are coordinated operations, some of them tied to nation-states, that integrated Claude into real-world attack chains.
One of the most serious cases involved Midnight Blizzard, the Russian state-sponsored hacking group identified by Microsoft. The group used Claude for reconnaissance, a critical early phase in any cyber operation in which attackers map networks, identify vulnerabilities, and choose targets. The group went on to breach Ukrainian and other European government networks, steal data, and maintain access to the systems it compromised. The inclusion of this case is significant because it shows a state actor using a mainstream AI product not just for auxiliary tasks like writing phishing emails, but for the intelligence-gathering work that precedes an intrusion.
Cybercriminal groups have been faster still to adapt. ShinyHunters, a group known for high-profile data breaches and extortion campaigns, used Claude in practically every stage of its hacking and extortion operations. That kind of end-to-end integration is exactly what AI safety teams worry about. A one-off malicious prompt is easy to block; a model embedded throughout a criminal workflow is much harder to contain. ShinyHunters did not treat Claude as a novelty. It treated the model as an operational assistant, available for whatever task the next attack required.
The same pattern appeared in disinformation, where Claude was used to support political influence operations in places as far apart as Kenya and Bangladesh. These campaigns focused on politics and used the tool to help create or amplify content aimed at shaping public opinion. The geographic range matters. AI-enabled disinformation is not a problem confined to Western democracies or large elections. It is spreading into smaller and more fragmented media environments, where a relatively modest volume of content can still have an outsized effect.
The darkest cases, however, were the ones involving biological weapons. In a handful of incidents, Anthropic discovered what appeared to be users of its tools attempting to develop potential bioweapons, including disease pathogens and toxins. The report does not describe these as fully developed weapons programs, and it is impossible to know from the outside how close any of these users came to producing something dangerous. But the fact that commercial AI assistants are now appearing in this space at all is a warning. Large language models can synthesize scientific literature, generate protocols, and answer detailed technical questions, and that capability is not automatically criminal. When users are specifically seeking to develop pathogens and toxins, however, the line between legitimate research and prohibited activity becomes both more important and harder to police.
For cybersecurity teams and policy makers, the report offers a useful taxonomy of current adversary behavior. State hackers, cybercriminal gangs, influence operators, and would-be biological weapons developers are all experimenting with the same tools that legitimate users rely on every day. The report also demonstrates why AI abuse cannot be treated as a single threat with a single defense. The attacks look different, move at different speeds, and require different kinds of intervention.
Why a Report Full of Blocked Attacks Is Not Quite Reassuring
Anthropic touts its success in the report, while implicitly humblebragging at the power of its tools. Every case study is framed as a case where the company’s safety systems caught something. But the overall effect of the case studies is more unnerving than reassuring. The report describes what Anthropic knows about, and even that limited view is startling. There is no guarantee that Anthropic has spotted every malevolent use of its AI, and the report does not claim to offer one.
Add in Anthropic’s competitors and the growing field of less safeguarded open-source AI tools, and the report starts to look less like a victory lap for AI guardrails and more like a preview of AI-enabled chaos to come. Commercial models with strict usage policies are only one part of a much larger ecosystem. Many open-source models can be downloaded, modified, and run without any oversight at all. The abuse Anthropic documents in its own systems is likely a fraction of what is happening across the broader AI landscape.
What did Anthropic’s latest misuse report reveal?
Anthropic’s latest misuse report says its systems blocked or contained a range of abusive uses of Claude, including state-linked cyber operations, cybercriminal hacking campaigns, political disinformation, and attempted bioweapon development. The report presents these as safety successes, but it also makes clear that Claude misuse is now widespread enough to require constant monitoring. None of the cases described is an isolated incident; each reflects a category of abuse that is expected to continue.
There is also a deeper problem with relying on a single company’s report as the measure of AI safety. The incentives are not aligned with full transparency. A lab that reveals too many details about adversarial use risks embarrassing itself, exposing vulnerabilities in its own moderation systems, and handing playbooks to other attackers. A lab that reveals too little risks looking complacent or evasive. Anthropic’s report sits somewhere in the middle. It provides enough detail to be credible, but not enough to allow outsiders to verify the scale of the problem or the effectiveness of the response.
What the report does establish, without meaning to, is that the boundaries around acceptable AI use are already being stress-tested by sophisticated adversaries. The question is not whether malicious actors will try to use AI systems for harm. The evidence says they already are. The question is whether the institutions responsible for securing those systems can keep pace with the speed at which the abuse is evolving.
Beyond Claude: The Expanding Battlefield of AI-Enabled Crime
Anthropic’s report describes one company’s visibility into its own platform. The wider threat environment, however, is full of cases where AI tools, unregulated marketplaces, and digital crime converge. This week’s law enforcement actions and platform safety revelations make clear that the problem extends far beyond any single chatbot. These cases are not all directly about Claude, but they are part of the same transformation: the internet is becoming a faster, more automated, and harder-to-police space.
The Xinbi Guarantee Takedown Exposes the Limits of Platform Self-Policing
Xinbi Guarantee grew, over its four-year lifespan, into the biggest illicit marketplace on the internet. It carried out an estimated $30 billion-plus in sales, most of which took the form of money laundering for “pig butchering” crypto scam operations largely based in Southeast Asia. The marketplace also facilitated sex trafficking and harassment for hire. All of it thrived on the Telegram messaging service.
Telegram shut down Xinbi a year ago, but the market rebuilt itself and eventually grew larger than ever. This week, the US government stepped in to do what Telegram did not. Authorities seized Xinbi’s channels on Telegram’s platform and sanctioned the market itself. The Justice Department simultaneously announced raids on 13 scam compounds in Madagascar, a sign that Western law enforcement is beginning to take seriously the epidemic of forced-labor crypto scamming. It is also evidence of how widely the operations have spread and how far beyond traditional financial hubs the criminal infrastructure has moved.
The Xinbi Guarantee case is a reminder that platform self-regulation has real limits. Telegram removed the marketplace once, and the marketplace came back bigger. That pattern is common in illicit online markets, but it is more dangerous now because the surrounding tools are more powerful. AI-generated content, automated translation, and AI-assisted customer service can all be used to rebuild a criminal operation faster than it can be torn down.
A Conti Ransomware Sentence Offers a Rare Accountability Moment
The ransomware group Conti was, until it officially disbanded in 2022, one of the most dangerous hacker crews in the world. US law enforcement says it hit more than a thousand victims, extorting millions and at one point disrupting government systems in Costa Rica so completely that it triggered a state of emergency. Conti was not just a group of freelancers; it operated like a professional organization, with salaries, recruitment, and public messaging. For years, its members appeared untouchable.
That changed this week, when 44-year-old Ukrainian Oleksii Oleksiyovych Lytvynenko was sentenced to four years in prison. Lytvynenko is one member of the Conti group, but his sentence is a rare example of a ransomware actor who will actually see the inside of a US prison. For years, ransomware operators have operated with near-immunity, often from countries that will not extradite them, while their victims struggle to recover. The Lytvynenko case does not mean the era of impunity is over, but it shows that law enforcement is slowly closing some of the gaps that have allowed ransomware crews to operate openly.
The case also underscores how much of the modern cybercrime economy is built on specialization. Ransomware gangs buy access from initial intrusion brokers, rent infrastructure, and outsource money laundering. AI tools, including chatbots and large language models, are now being inserted into that supply chain. The same capabilities that help developers write code faster are helping attackers craft more convincing lures, analyze stolen data, and automate parts of their operations.
Facebook’s AI-Generated Child Abuse Videos Slip Through Moderation Gaps
Facebook is hosting a large network of accounts that upload AI-generated videos depicting violence against children. A cataloging effort that lasted for days kept finding more videos than it could count. The clips show young children being beaten, burned, confined, and starved. Many attract thousands of reactions from users who appear to believe the footage is real.
The accounts were found mostly by opening one account and then following Facebook’s recommendation feed, which supplied a continuous stream of similar videos. That is a telling detail. It suggests Meta’s own systems can already identify the category of content the company says it bans. The recommendation engine was doing exactly what it was designed to do: finding more of what a user wanted to see. The problem is that what the user wanted to see was AI-generated child abuse.
Eight of the accounts were reported through Facebook’s standard user reporting channel. Meta removed two of them, with one removal happening only after the initial report was rejected. Several decisions took more than a week. The company deleted most of the videos sent to its press office, but initially left others up, including one showing a child locked in a freezer.
Meta’s written policy bars depictions of nonsexual child abuse, whether real or synthetic, with exceptions for art, cartoons, movies, and games. The policy does not say whether AI-generated video falls under those exceptions. That ambiguity is not accidental. AI-generated content sits in a gray zone between clearly banned material and protected expression, and the consequences of getting the judgment wrong are severe. If the content is removed, Meta faces accusations of censorship. If it is left up, it becomes part of a growing pool of realistic abuse content that could traumatize viewers, normalize violence against children, and potentially make it harder for investigators to distinguish real abuse from synthetic material.
The Facebook case also raises a broader question about AI platforms and content moderation. The videos were generated by AI and then distributed on a major social network. That means the harm is not coming from a single model or a single company. It is coming from an ecosystem in which generative tools and distribution platforms are both being used irresponsibly. Meta told reporters that some flagged links did not break its rules and asked them not to write otherwise. The public record, however, includes videos that depict children being starved, confined, burned, and beaten, and a recommendation system that happily fed users more of the same.
The Pattern Beneath the Chaos
These cases are different in their details, but they share a common structure. Adversaries are taking whatever new tools are available and integrating them into existing criminal or political projects. Russian hackers used Claude to strengthen reconnaissance. Cybercriminals used it to streamline extortion. Disinformation operators used it to amplify political content. Someone used it to research pathogens. Meanwhile, illicit marketplaces rebuilt themselves after takedowns, ransomware operators continued to operate until a rare prosecution caught up with them, and social media platforms distributed AI-generated abuse content through recommendation systems that understood it all too well.
The common thread is speed. The abuse is moving faster than the response. Anthropic can publish a report and point to blocked cases, but it cannot demonstrate that its visibility is complete. Telegram can shut down a marketplace, but the marketplace can come back larger. Law enforcement can win a ransomware sentence, but the broader ransomware economy remains resilient. And Meta can maintain policies against child abuse content, but those policies have not kept pace with AI-generated video that looks realistic enough to attract thousands of reactions from users who think it is real.
For organizations responsible for security and safety, this is not a moment for easy optimism. The era of AI-enabled abuse is already here, and it is distributed across every corner of the internet. The tools that make AI powerful also make it useful to bad actors. The systems that make platforms engaging also make them dangerous when the content they recommend is harmful. Guardrails can be strengthened, laws can be enforced, and platforms can be pressured to do better. But the underlying dynamic is unlikely to change. Malicious users will keep finding ways to exploit every new capability, and the institutions trying to stop them will have to keep running just to stay in place.
The more honest lesson of Anthropic’s report, read alongside the Xinbi Guarantee take down, the Conti conviction, and the Facebook abuse network, is that safety is not a feature that can be installed once and then trusted. It is a continuous, adversarial process. The next major AI system may have better guardrails, but the attackers will have learned from the last one. The only realistic response is to assume that Claude misuse, and AI misuse more broadly, is not going away. It is becoming part of the operating environment of the internet, and everyone who builds on that environment will have to account for it.