Particle.news
Download on the App Store

Anthropic Discloses State‑Aligned Misuse and Large‑Scale Extraction of Claude

The company warned fragmented prompts plus industrial‑scale distillation have let foreign actors capture model capabilities despite account bans and disruptions.

Overview

  • Anthropic published a 154‑page threat report this week saying it detected, disrupted, and banned accounts tied to multiple state‑aligned campaigns that ran from December 2025 through August 2026.
  • The report documents clear cases where operators used Claude to support weapons work and targeting, including a Yemen cell that used Claude Code to develop guidance software and an Iran‑linked actor that compiled targeting handbooks on U.S. Navy vessels.
  • Anthropic found China‑linked projects that used Claude for military engineering and surveillance and alleges industrial‑scale distillation efforts, including one campaign it says routed more than 151 million exchanges through Alibaba to harvest Claude outputs.
  • The company says attackers evaded model guardrails by breaking complex tasks into many benign requests, using persona or jailbreak prompts, and moving assembled toolkits offline so some capabilities survived account shutdowns.
  • Security experts and Anthropic call for stronger defenses such as session‑level monitoring or API proxies, mandatory incident reporting, and cross‑industry coordination because per‑prompt filters can miss cross‑session assembly and downstream leakage.