(Updates with additional details about malicious use of Claude, including distillation efforts by China-based AI labs, throughout.)
Anthropic identified and disrupted operations by threat actors using Claude for malicious activities, including cyberattacks, surveillance, scams and fraud, weapons development and model distillation, the company said Thursday.
Anthropic's report covered efforts for malicious use of its models from December through August.
The identified threat actors included suspected state-sponsored groups, financially motivated criminals, and politically motivated individuals, and Anthropic has shared intelligence with authorities and industry partners where appropriate, the company said.
Anthropic said Claude Haiku, Sonnet and Opus models were used in all identified cases, while no malicious activity was found involving Claude Fable or Mythos, except for one illicit distillation case.
Distillation cases involved unauthorized labs attempting to extract and harvest reasoning traces from Anthropic models, with China-based AI labs including DeepSeek, Xiaomi and Moonshot allegedly feeding conversations between their own models and users into Claude and then using Claude's responses as training data to distill its capabilities, Anthropic said.
Anthropic said it detected and disrupted unauthorized distillation attacks by China-based labs targeting its Opus-class models.
In particular, Alibaba (BABA)-affiliated operators allegedly conducted the largest illicit distillation operation, targeting chain-of-thought reasoning transcripts of Opus 4.6 and 4.7, Anthropic said.
Alibaba also allegedly used Claude to support its AI research and development efforts, including developing reinforcement-learning environments, internal model-development infrastructure and model architecture research, Anthropic said.
According to Anthropic, Alibaba initially used a pool of nearly 5,000 fraudulent accounts to access Claude, which were subsequently banned. Alibaba operators then switched to another pool of accounts that Anthropic said were also found to be funneling requests from DeepSeek and Xiaomi, indicating that the same proxy service networks can be used by multiple organizations.
Anthropic said it has introduced additional AI safeguards designed to make it more difficult for unauthorized labs to distill Claude's capabilities.
Comments