Anthropic: China, Iran Use AI for Espionage

0
14

Key Takeaways

  • Anthropic disclosed that state‑aligned actors from China, Iran, and West African nations abused its Claude models to conduct surveillance, weapon design, and illicit biological research between January and July.
  • The surveillance campaigns specifically targeted diaspora and dissident groups—including Hong Kong pro‑democracy figures, Tibetan and Falun Gong communities, and Iranian minority activists abroad.
  • Iranian operatives used Claude to build social‑media‑based identification tools, while a Malian contractor employed the model to craft intelligence‑gathering software.
  • Chinese developers allegedly rerouted user queries through fraudulent accounts to “distill” Claude’s outputs, secretly training their own models (Moonshot and Deepseek) and exposing sensitive user data.
  • Anthropic also blocked attempts to design weapons and conduct questionable pathogen research, though the intent behind the biological‑work cases remained ambiguous.
  • The lab warned that AI is increasingly replacing traditional engineering workforces in state‑sponsored espionage and highlighted the need for stricter safeguards against model misuse.

Anthropic Reveals State‑Sponsored AI Abuse
On Thursday, Anthropic published a report detailing how it uncovered and shut down multiple instances of state‑sponsored surveillance that leveraged its Claude artificial‑intelligence models. The incidents, detected between January and July, originated in China, Iran, and West African jurisdictions. According to the report, these campaigns “targeted the same diaspora and dissident communities these regimes have historically targeted.”

Surveillance Targets Ethnic and Political Dissidents
The misuse focused on groups long persecuted by the implicated governments. Anthropic noted that the operations aimed at “pro‑democracy figures in Hong Kong, Tibetan and Falun Gong communities across Asia, and Iranian minority communities and opponents of the Iranian regime abroad.” By repurposing Claude’s language capabilities, actors sought to identify, track, and intimidate these populations online.

Iranian Social‑Media Identification Scheme
In one highlighted case, Iranian actors devised a method to identify individuals through their social‑media profiles using Claude. The report quoted the lab’s observation: “In one case, Iranian actors developed a way to identify people through their social media accounts.” This technique allowed the regime to link pseudonyms to real‑world identities, facilitating repression of dissent.

Malian Contractor Builds Intelligence Tool
A separate incident involved a contractor working for Malian national‑security authorities. The contractor employed Claude “to design the underlying software that enabled the intelligence gathering.” Anthropic warned that such use demonstrates how AI can replace traditional engineering teams in constructing spy‑craft infrastructure.

AI Replacing Human Engineering Workforce
The report emphasized a broader trend: “AI is now being used in place of an engineering workforce.” By automating code generation, data analysis, and pattern recognition, state actors can scale surveillance operations far beyond what manual teams could achieve, lowering the barrier to entry for sophisticated espionage.

Weaponization and Illicit Biological Research Blocked
Beyond espionage, Anthropic disrupted attempts to use Claude for designing weapons and conducting questionable biological research. While the lab did not attribute clear malicious intent to the biological‑work cases, it noted that the research involved “work around the mosquito‑born chikungunya virus, a ‘highly‑pathogenic’ strain of the bird flu, a family of viruses that include smallpox and mpox, venoms and other toxins.” The scientists involved were described as “working scientists,” and Anthropic refrained from naming them to avoid potential harm.

Chinese Developers Accused of Model Distillation
Anthropic also accused Chinese developers of deceptively routing user queries through fraudulent accounts to harvest Claude’s outputs. The practice, known as “distilling,” involves using one AI model to train another, effectively stealing computational resources. The report claimed that Chinese firms Moonshot and Deepseek secretly employed this tactic.

Massive Query Rerouting via Fake Accounts
In a striking example, over a ten‑day period Moonshot relayed almost 300,000 customer requests to Anthropic “through a ‘network of 5,380 fraudulent accounts, most of which appeared to be located in Singapore and Japan.’” The report warned: “We do not know if Moonshot notified their customers that their requests were being rerouted to Anthropic and exposed to a third party.” This covert data harvesting potentially violated privacy agreements and exposed sensitive user information.

Deepseek Mirrors Similar Tactics
Deepseek employed comparable methods, according to Anthropic’s findings. Though the lab did not disclose the exact volume of requests handled by Deepseek, it affirmed that the company used the same deception‑based pipeline to obtain Claude‑generated responses for its own model training.

Ethical and Security Implications
The report underscores that AI misuse is no longer a theoretical concern but an active component of statecraft. By leveraging large language models for surveillance, weapon design, and illicit research, actors can amplify their capabilities while obscuring accountability. Anthropic’s decision to publicize these cases aims to raise awareness among policymakers, tech firms, and the broader AI community about the urgent need for robust detection mechanisms, stricter usage policies, and international cooperation to curb AI‑enabled repression.

Conclusion: A Call for Vigilance
Anthropic’s disclosures serve as a stark reminder that the same technology driving innovation can be repurposed for harm when safeguards falter. As AI models become more powerful and accessible, the balance between openness and security will dictate whether these tools empower societies or enable authoritarian control. Continued transparency, vigilant monitoring, and collaborative defenses will be essential to ensure that AI serves the public good rather than becoming a conduit for state‑sponsored abuse.

https://sg.news.yahoo.com/china-iran-among-countries-used-015023995.html

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here