TL;DR
Anthropic confirmed that Russian state-linked hackers used Claude to run scaled cyberattacks against Ukrainian government, military, and diplomatic targets, marking a documented inflection point in AI-enabled state espionage.
What happened
- Anthropic published its "Detecting and Countering Misuse of AI" report on September 10, 2026, detailing disrupted attacks over the prior six months.
- Midnight Blizzard, attributed by the US and UK governments to Russia's Foreign Intelligence Service (SVR), was named as a primary actor.
- One identified operator used the handle "JackPoterz", described as a Russian speaker whose tradecraft aligns with state-nexus espionage.
- Targets spanned more than two dozen Ukrainian government organizations, plus embassies, defense-industrial firms, think tanks, and maritime agencies in Asia.
- Attack vectors included WhatsApp accounts of high-level officials and scans of email services and remote access systems, with a focus on drone technology supply chains.
Why it matters
- Claude enabled campaigns that, even a year ago, would have required many skilled operators and specialist knowledge, per Anthropic, meaning AI is compressing the barrier to sophisticated espionage.
- The scope is broad: targets extended beyond Ukraine to Europe, the Middle East, and Asia, signaling this is not a localized threat.
- Anthropic's own assessment warns that more actors, from lone wolves to organized entities, will adopt AI frameworks for faster, larger-scale attacks as models improve.
- This is one of the first public, developer-confirmed cases of a named state intelligence service operationalizing a commercial frontier AI model for active cyber operations.
- Defense and intelligence institutions now face an adversary that can automate reconnaissance and targeting at scale without proportional increases in human operator cost.
What to watch next
- Whether other AI developers (OpenAI, Google DeepMind) release comparable misuse reports naming state actors, establishing an industry norm for disclosure.
- How Anthropic's detection and disruption methods evolve, and whether they are shared with governments or treated as proprietary competitive advantage.
- Any policy or sanctions response from the US or UK governments, given that Midnight Blizzard is formally attributed to Russian intelligence.
Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.