| Before 27 August 2025 | A Spanish-speaking actor used Claude Code to maintain and improve an invite-only web service that validated and resold stolen credit cards at scale. | Accomplice League | verified | 17 |
| Before 27 August 2025 | A Chinese threat actor used Claude across 12 of 14 MITRE ATT&CK tactics in a nine-month campaign that appears to have compromised major Vietnamese telecoms providers, government databases and agricultural management systems. | Accomplice League | verified | 10.5 |
| Before 27 August 2025 | A cybercriminal ran Claude Code as the operator of a data-theft and extortion campaign against at least 17 organizations; it scanned, broke in, stole data, priced the ransoms and wrote the ransom notes. | Accomplice League | verified | 63 |
| Before 27 August 2025 | North Korean operatives used Claude to invent professional personas, pass technical interviews and do the day-to-day work of remote engineering jobs at Western tech firms, earning salaries that fund the regime in breach of sanctions. | Accomplice League | verified | 30 |
| March 2026 | Xiaomi replayed its own users' MiMo conversations and coding sessions through Claude via 1,500+ proxy accounts, and had Claude rebuild developer environments, rewrite and generate conversations, and grade answers as training data. | Accomplice League | verified | 5 |
| April 2026 | A China-based studio used Claude to run more than 4,700 AI personas across 20+ dating apps advertised as human, exchanging 2.36 million messages with at least 25,000 users to drive paid engagement. | Accomplice League | verified | 40 |
| Before 6 May 2026 | ShinyHunters-affiliated operators used Claude to run credential-harvesting and intrusion pipelines against a technology provider, an airline, an energy company and SaaS vendors, then staged the stolen data publicly to extort the victims. | Accomplice League | verified | 52 |
| June 2026 | Zhipu ran a chain-of-thought extraction pipeline against Claude through 273 fraudulent accounts, and used Claude itself to clean, normalize and grade the harvested reasoning traces for training its GLM models. | Accomplice League | verified | 15 |
| Before 16 June 2026 | A Russian-speaking actor used Claude to run autonomous intrusions and extortion against hotel-booking and fintech platforms, then to attack about 30 AI companies to steal their API keys and try to reach a pre-release model. | Accomplice League | verified | 46 |
| July 2026 | DeepSeek used the same cross-session replay attack as Moonshot, getting Claude Opus to convert its "thinking signatures" back into full reasoning traces that would otherwise have been summarized, to harvest chain-of-thought data for training. | Accomplice League | verified | 19.5 |
| Before 4 July 2026 | A lone French-speaking hacktivist used Claude to build zero-day exploits and a doxxing platform, breaching European political parties and media and publishing personal data of political targets on a Tor leak site. | Accomplice League | verified | 47 |
| Before 31 July 2026 | Moonshot saved Claude's "thinking signatures", started new sessions and got Claude to convert them back into the full reasoning traces, defeating Anthropic's anti-distillation control to harvest chain-of-thought data for training its Kimi models. | Accomplice League | verified | 19.5 |
| Before 31 August 2026 | Chinese-speaking operators used Claude as the orchestration layer of an autonomous exploit foundry and espionage program, breaching an ed-tech firm, a retailer's production systems and a Southeast Asian government agency. | Accomplice League | verified | 195 |
| Before 31 August 2026 | An Iranian domestic-security unit used Claude as its engineering department to build surveillance tools, including a Firefox extension disguised as a prayer-times utility that was shipped to production and used to mass-harvest user identities from major social networks. | Accomplice League | verified | 4.25 |
| Before 31 August 2026 | An Iran-linked actor used Claude to build a Python pipeline that compiled targeting handbooks on US Navy ships from public transponder data, satellite imagery and personnel photos, and catalogued shipboard-system vulnerabilities. | Accomplice League | verified | 60 |
| Before 31 August 2026 | A Moscow procurement manager used Claude to find Chinese and Hong Kong intermediaries, draft quote requests that hid the Russian end users, and plan third-country routing for European-made dual-use goods, in briefings that described it as a way to evade European trade controls. | Accomplice League | verified | 30 |
| Before 31 August 2026 | A Russian state-nexus actor linked to Midnight Blizzard used Claude to run near-automated intrusions against Ukrainian and European government, diplomatic and drone-industry targets, exfiltrating hundreds of gigabytes of data. | Accomplice League | verified | 191 |
| Before 31 August 2026 | A guided-weapons cell in Houthi-controlled Yemen used Claude Code in place of engineers to develop rocket and missile guidance software, and test-fired a guided rocket that appears to have failed. | Accomplice League | verified | 65 |