Anthropic details influence operations, fraud and malware misuse of Claude
Anthropic reported four cases of malicious Claude use and said it banned the accounts associated with the activity.
Quick answer
What malicious uses of Claude did Anthropic identify and counter?
Anthropic reported that actors used Claude in an influence operation, an effort involving leaked security-camera credentials, a recruitment fraud campaign and malware development. The company said it banned the associated accounts and used conversation-analysis techniques and classifiers to detect, investigate and counter the activity.
Key takeaways
- Anthropic described four cases in which actors allegedly used Claude for influence operations, credential-related activity, recruitment fraud and malware development.
- The company said an influence-as-a-service operation used Claude to coordinate more than 100 social media bot accounts across Twitter/X and Facebook.
- Anthropic said it banned every account associated with the activity described in the report.
- The company said it used Clio, hierarchical summarization and classifiers to analyze conversations and identify misuse patterns.
Anthropic published a report describing four cases in which actors allegedly misused Claude for coordinated political influence, activity involving leaked security-camera credentials, recruitment fraud and malware development. The company said it identified and banned the accounts associated with every case.
Anthropic said its intelligence team used techniques from its Clio and hierarchical summarization research to analyze large volumes of conversation data. It combined those methods with classifiers that examine user inputs for potentially harmful requests and assess Claude’s responses before or after delivery.
Coordinating social media bots
The company identified what it called a financially motivated influence-as-a-service operation that managed more than 100 bot accounts across Twitter/X and Facebook. Anthropic said the operation engaged with tens of thousands of authentic social media accounts in multiple countries and languages.
According to Anthropic, the operator used Claude to create and maintain personas with distinct political alignments, generate politically aligned responses and prepare prompts for image-generation tools. Claude also helped determine whether bot accounts should like, share, comment on or ignore specific posts according to clients’ political objectives.
Anthropic said the narratives resembled those associated with state-affiliated campaigns, but it did not confirm that attribution. The company also said none of the operation’s content became viral. It described the activity as sustained engagement promoting moderate political perspectives for clients outside the United States.
Credentials, recruitment fraud and malware
In another case, Anthropic said a sophisticated actor attempted to build systems for collecting exposed usernames and passwords associated with security cameras and testing credentials against internet-facing targets. The actor used Claude to rewrite a scraping toolkit, create scripts for collecting target URLs, process posts from stealer-log Telegram communities and improve search systems. Anthropic said it had not confirmed successful deployment.
The company also reported banning an actor conducting recruitment fraud primarily against job seekers in Eastern European countries. Anthropic said the operation impersonated hiring managers from legitimate companies and used Claude to refine language, develop recruitment narratives, create interview material and format messages. Operators submitted poorly written, non-native English for Claude to polish, according to the report. Anthropic said it had not confirmed successful scams from the operation.
A fourth case involved an actor with limited coding skills who used Claude to develop tools for doxing and remote access. Anthropic said the actor’s toolkit advanced to include facial recognition and dark-web scanning, while a malware builder progressed from a batch-script generator to a graphical interface for producing malicious payloads designed to evade security controls and retain access. The company did not confirm real-world deployment of the malware.
Detection and enforcement
Anthropic said its intelligence program seeks harms missed by standard detection systems and provides context about how actors misuse its models. The company said findings from each case were incorporated into broader controls intended to detect and prevent adversarial use more quickly.
Source: Anthropic’s “Detecting and countering malicious uses of Claude: March 2025,” published April 23, 2025.
Frequently asked questions
- What cases did Anthropic describe?
- Anthropic described an influence-as-a-service operation, activity involving leaked credentials associated with security cameras, a recruitment fraud campaign and a novice actor developing malicious tools.
- Did Anthropic confirm that the cyber and fraud efforts succeeded?
- No. Anthropic said it had not confirmed successful deployment of the security-camera credential effort, recruitment scams or malware.
- How did Anthropic respond to the identified activity?
- The company said it detected, investigated and banned the accounts associated with the cases. It also said each case informed its broader controls for detecting adversarial use.
- How was Claude used in the influence operation?
- Anthropic said Claude helped maintain political personas, generate responses and decide whether bot accounts should like, share, comment on or ignore particular social media posts.