Threat reports usually read like insurance paperwork. Anthropic’s latest reads like an indictment. Published this week, the company’s threat intelligence report catalogues two years of attempted misuse of its models — and it does something no frontier lab has done before: it names other AI companies.
The most consequential passages concern distillation: systematic attempts to extract Anthropic’s capability into smaller, cheaper models in violation of its terms of service. The report attributes industrial-scale operations to DeepSeek, Moonshot AI, and MiniMax, with additional activity linked to Alibaba-affiliated operators. These are not anonymous scraping rings. They are China’s most prominent frontier-adjacent labs, named in a competitor’s compliance filing — and the publication lands two days after a CISA, NSA, and FBI advisory already listed DeepSeek among Chinese actors distilling US models at scale.
The state campaigns are darker. Russian state-aligned actors used Claude Code — the same coding agent Anthropic markets to enterprises — to conduct reconnaissance and develop implants against Ukrainian government and military organizations, per Reuters’ reporting on the document. A separately disclosed Iranian-linked campaign targeted US naval forces and defense personnel. In both cases the model needed no agency of its own; it was an instrument in a human operator’s hands, which is precisely the threat model most safety frameworks under-weight.
The Naming Game
Attribution is the real escalation. A lab that suspects distillation can throttle accounts and quietly refund credits; a lab that publishes names has chosen a side in a trade dispute Washington is already litigating. Anthropic blocked more than 5,000 restricted entities in the reporting period, and the report frames enforcement as an ongoing operation rather than a posture. But naming DeepSeek and Moonshot hands US policymakers a ready-made narrative — and gives Beijing a fresh grievance about extra-territorial enforcement. The report is simultaneously evidence, marketing, and diplomacy.
For Anthropic, the document is also institution-building. The company has now disclosed four internal incidents this year, engaged METR for external evaluation, and publishes its adversary file on a cadence. Transparency has become a competitive differentiator: the lab most willing to describe its own misuse is also the lab asking regulators to pace the frontier. Whether that reads as leadership or positioning depends on how much of the file the next report redacts.
The Takeaways
- Anthropic’s threat report names DeepSeek, Moonshot AI, and MiniMax in industrial-scale distillation — a first for a frontier lab.
- Russian state-aligned actors used Claude Code against Ukrainian targets; an Iranian-linked campaign targeted US naval forces.
- Attribution turns a safety report into a geopolitical document — and lands two days after CISA, NSA, and FBI named DeepSeek in a distillation advisory.

