Anthropic reveals breach of Cloud models used to develop missile software and conduct espionage, with task disaggregation breaking security barriers
Listen to this article
Read by Anchor
Anthropic disclosed in a recent intelligence report that it had thwarted a series of targeted operations that exploited Cloud models for military and espionage tasks, including designing missile guidance software, conducting electronic espionage campaigns, and performing mass surveillance. The incidents were first observed by the company in northern Yemen, where operators attempted to use the model as a substitute for software engineers to write guidance and control code for a guided projectile and a long-range ballistic missile. Although the system’s internal defenses blocked many requests, the company confirmed that other requests slipped through after the operators deliberately concealed their ultimate goals and distributed the programming tasks across separate chat sessions to avoid detection through a single code command. The company said it banned the involved accounts and shared threat data with partners in the public and private sectors, noting that there was no evidence of a fully deployed operational weapon, while noting indicators of a unsuccessful launch test.
Disassembling commands across multiple sessions shattered the assumption that textual security barriers were sufficient against the engineering of rockets and conventional weapons.The threat report also indicated that model exploitation extended to cyber-espionage operations conducted by state-linked actors, including a Russian activity bearing the imprint of the Midnight Blizzard group known as APT-29. That group relied on automated workflows that managed the operation almost entirely, from preparatory phishing and data theft against Ukrainian, European and diplomatic targets, including drone-manufacturing firms. In a parallel track, the company disrupted activity led by university students in China’s Hunan province who used the Cloud model’s formatting and engineering layer to build an offensive program targeting government and corporate networks in the Middle East, Europe and Southeast Asia, prompting the company to impose additional monitoring on those patterns.
The violations did not stop at malicious code; they also extended to psychological and field intelligence operations in the region. The company banned three Iranian accounts linked to official propaganda institutions, including the Islamic Culture and Relations Organization and a guidance chamber in a scene that disseminates Revolutionary Guard narratives. Investigations revealed the construction of structured profiles that categorize targets by geographic location, demographic composition and political leanings. The company described the most operationally mature case as the observation of a Chinese account whose operators lacked Arabic knowledge yet employed Cloud to manage a recruitment and infiltration operation that lasted days, targeting Uyghur individuals in Syria; the model crafted messages in a precise local dialect and handled translation of replies instantly and interactively.
These events coincided with internal turmoil at the company, following a leak that revealed unauthorized access to an early version of the Opus 4.6 model by external systems, which was then followed by the resignation of researcher Jacob Coxon, who warned of uncontrolled existential risks supported by the testimony of other scientists such as Ivan Hopinger, prompting U.S. legislators to renew calls for mandatory regulatory frameworks. At the same time, the company is engaged in a sharp dispute with the U.S. Department of Defense after the Pentagon placed it on a supply-chain risk list for refusing to lift ethical restrictions on autonomous weapons and internal oversight, before a California judge ruled the decision unlawful. Despite this clash, reports indicated that the Pentagon has been using Cloud models for military tasks inside Venezuela and Iran, while the company seeks to regain its standing within the Washington defense-industry complex.
This shift requires tech and security leaders in the Gulf, Egypt and the Levant to immediately recalibrate their cyber-security assumptions.The success of non-Arabic-speaking actors in launching social intrusion operations and security recruitment using sound local dialects means that language clumsiness is no longer a reliable indicator for detecting phishing in Arab organizations. Likewise, the fragmentation of malicious code or military control software across independent chat sessions undermines the effectiveness of real-time monitoring tools that rely on inspecting each entry individually, prompting information security managers to shift to cumulative contextualThe success of non-Arabic-speaking actors in launching social intrusion operations and security recruitment using sound local dialects means that language clumsiness is no longer a reliable indicator for detecting phishing in Arab organizations. Likewise, the fragmentation of malicious code or military control software across independent chat sessions undermines the effectiveness of real-time monitoring tools that rely on inspecting each entry individually, prompting information security managers to shift to cumulative contextual analysis of model behavior within work environments. These facts also highlight the cost of fully relying on Western cloud APIs that swing between military classification battles and external oversight controls, reinforcing the urgent operational need to develop locally governed institutional models that are strictly independent and ensure that critical infrastructure remains insulated from intrusion risks or sudden outages.