Anthropic says it spent the past eight months tracking down and shutting down several operations aimed at misusing its Claude models. The company’s biggest claim in this batch: DeepSeek, Moonshot and MiniMax allegedly ran campaigns designed to siphon off Claude’s capabilities and feed them into their own systems.
Before reading too much into that, it’s worth being clear about what the report actually is. Published in September 2026, it isn’t a security bulletin about a specific bug, device, account or software version, and there’s nothing in it telling users to take any action. Anthropic also doesn’t present evidence that a particular flaw in Claude was actively exploited. This is a rundown of misuse patterns the company says it has observed from its own vantage point as the model’s maker — not an alert asking customers to patch something or change their behavior.
Anthropic describes the alleged campaigns tied to the three labs as “industrial” in scale, and says the goal was to extract Claude’s capabilities to strengthen rival models. But the material released so far doesn’t spell out how these operations were supposedly carried out, how big they were, how long they ran, or which specific capabilities — if any — actually ended up transferred to competing systems.
Those gaps matter. Without them, there’s no way to independently judge whether the attempts succeeded or what damage, if any, resulted. That said, the missing detail doesn’t erase the report’s central claim: Anthropic is arguing that a frontier AI model can itself become a target of coordinated efforts by other AI developers, not just a tool that bad actors point at other people. From the company’s perspective, the immediate takeaway is that its detection systems and safeguards held up against what it describes as well-organized adversaries.
The report also references a cyberespionage campaign that Anthropic says it detected and disrupted in September 2025, calling it highly sophisticated. But the released material doesn’t name who was targeted, who was behind it, or what the fallout looked like. Without that context, this incident reads as a footnote next to the more pointed accusations against DeepSeek, Moonshot and MiniMax.
Anthropic further states that malicious actors are actively probing for ways around Claude’s guardrails. That’s consistent with an environment of persistent attempts to test the model’s defenses, but based only on what’s been made public here, it doesn’t amount to proof that any specific vulnerability is currently being exploited in the wild.
In short, the report hands out names and points to a trend — rival AI labs allegedly trying to reverse-engineer or extract value from a competitor’s model — without the underlying data needed to gauge how serious or widespread the problem really is. Anthropic hasn’t said whether more detailed findings, methodology, or evidence will follow, leaving outside observers to take the attribution largely on the company’s word for now.