Anthropic details Claude misuse in deception, surveillance, and malware
Anthropic details Claude misuse spanning dating personas, activist impersonation, and malware, raising concerns about what stronger models could enable.

Anthropic published a new Threat Report on September 10, detailing selected cases of Claude misuse it says it disrupted from December 2025 through August 2026. The cases span mass deception, surveillance, malware, and possible weapons applications.
As The Rundown reported, Anthropic accused seven Chinese labs of relying on thousands of fraudulent accounts to gather Claude responses for model training. It named Alibaba, DeepSeek, Moonshot, Xiaomi, Zhipu, SenseTime, and MiniMax. The company also alleges that Moonshot and DeepSeek sometimes served Claude to customers as their own model, then trained on those responses.
Thousands of personas and live impersonation
In one operation, Anthropic says Claude powered more than 4,700 dating app personas that exchanged 2.36 million messages with at least 25,000 users over two weeks in April 2026. Humans handled the video calls.
Another actor drew on roughly 8,400 Telegram posts to imitate an activist's writing style in live conversations with his contacts. The report also describes an operation that automated malware rebuilding after security detections.
Weapons flags and surveillance
Anthropic flagged five biology cases involving scientists for possible weapons applications, while saying it “does not assert that they intended harm.”
In Yemen, an actor turned to Claude Code to build rocket guidance software and returned for advice after an apparently failed test flight. The report provides no evidence of an operational weapon.
Anthropic also describes a consultant who built a system for Mali's spy agency aimed at monitoring approximately 25 million SIMs. The scale of any actual interception remains unclear.
Why it matters
The disturbing detail is how much work the operators asked Claude to perform. Maintaining thousands of personas, imitating a trusted contact, and revising malware all demand repeated effort. Automating that work could let an operator sustain a larger operation with fewer people. The dating, impersonation, and malware examples involved models at the Opus tier or below, making the prospect of stronger systems handling more of that work troubling.
For people on dating apps, the human video calls complicate a familiar trust signal. Speaking to a real person would not establish who wrote the surrounding messages. For an activist's contacts, a copied writing style could make an exchange feel credible while someone else directs it.
Security teams face a different problem when an operator automates malware revisions after detection. A blocked file may mark one interruption in a longer effort. The practical concern is that less manual work could let an operator make and review more attempts.
The Mali case also shows a limit to account bans. Anthropic says its bans left the local deployment in place. Software built with Claude can run elsewhere after model access is cut off. Addressing the surveillance risk would also require action on that deployed system.
Access rules bring their own tradeoffs. Anthropic's July 2 explanation of Fable 5's cyber safeguards describes stricter screening, access controls, safety training, and monitoring. The company acknowledges that broader blocking also rejects benign requests, a cost for people seeking help with legitimate security work.
Anthropic's September 10 companion study gives a reason to worry about specialized work, too. It examines linking accounts, finding locations, and simulated weapons engineering. In one test with synthetic data, the company says Mythos Preview assessed a sample of roughly 37,000 words in about 11 minutes. Anthropic argues that such capabilities could reduce dependence on scarce analysts and engineers.
Performance varied by task. Anthropic found that Opus 5 outperformed models in the Mythos family on a simulated weapons guidance task. The synthetic data and simulations do not establish how much more effective an attacker would become in practice.
Sources & further reading
This story builds on reporting from The Rundown newsletter on September 11, 2026.