Anthropic recently disclosed the disruption of several state-sponsored surveillance operations utilizing its Claude AI models. The San Francisco-based lab identified malicious activities originating from China, Iran, and West Africa between January and July 2026.

Advertisement

Moonshot’s 300,000-request data distillatiion scheme

Chinese developers Moonshot and Deepseek have been accused of deceptive practices aimed at improving their own AI models through "distillation." According to a report released by Anthropic on September 10 , 2026, these firms used Claude to generate responses which were then used to train their own systems.

The report details a specific ten-day window where Moonshot allegedly rerouted massive amounts of data. The company reportedly relayed nearly 300,000 customer requests to Anthropic using a network of 5,380 fraudulent accounts. These accounts were designed to appear as though they were located in Japan and Singapore to mask the true nature of the traffic.

Targeting dissidents in Hong Kong and Iran

State-sponsored actors have increasingly leveraged artificial intelligence to monitor vulnerable populations. Anthropic reported that surveillance campaigns specifically targeted pro-democracy figures in Hong Kong, as well as Tibetan and Falun Gong communities across Asia.

The methods used by these actors varied by region. in one instance, Iranian actors developed techniques to identify specific individuals through their social media presence. Additionally, a contractor based in Mali used Claude to assist in designing software intended for intelligence gathering. These activities reflect a growing trend where AI is weaponized for political repression against ethnic minorities and dissidents.

Preventing research on H5N1 and smallpox

Anthropic's safety protocols also intercepted attempts to utilize the Claude model for biological research that could lead to weaponization. The lab identified and blockeed queries related to several highly dangerous pathogens.

Specific areas of concern included research involving the chikungunya virus, a highly pathogenic strain of H5N1 bird flu, and families of viruses including smallpox and mpox. While the lab identified these topics, Anthropic chose not to name the specific individuals or laboratories involved to prevent further harm to those parties.

The mystery of the 5,380 fraudulent accounts

Despite the scale of the data interception, several critical details remain unverified. As Anthropic reported, it remains unclear whether Moonshot provided any notification to its customers that their data requests were being rerouted to a third party .

Furthermore, while the lab identified the biological research queries, the true intent behind the scientists' work remains an open question. It is currently unknown if these researchers were acting under state direction or if the queries were part of legitimate, albeit high-risk, scientific inquiry.