Skip to content
Russian hackers used Claude against Ukraine | Ukrainian News

Russian hackers used Claude against Ukraine | Ukrainian News

Biz.Liga September 11, 2026

Hackers linked to Russia used AI agents named Claude to steal data from drone manufacturers in Ukraine

A Russian cyberintelligence group used the artificial intelligence system Claude to launch attacks against Ukrainian government, military, and diplomatic institutions, as well as manufacturers of military drones. This is reported in a recent reports Anthropic.

Anthropic links the activities of the GTG-20006 group to Russia’s Foreign Intelligence Service. The company’s attribution is consistent with public information linking this group to Midnight Blizzard.

According to Anthropic, the group targeted more than 20 organizations, including ministries, intelligence and defense agencies, embassies, think tanks, and defense industry companies. Most of the targets were located in Ukraine and Europe.

Hackers automated a significant portion of their operations using AI agents based on Claude: they engaged in reconnaissance, phishing, system intrusion, and data theft. The hackers also scanned email services and remote access systems of more than two dozen Ukrainian government organizations.

Another area of focus was the reconnaissance of Ukrainian military drone manufacturing. The attackers compromised the email accounts of at least two manufacturers of drone components, targeted a manufacturer of military drones, and stole the entire proprietary software package developed by a software developer for a drone’s computer vision system.

After that, over the course of several days, they used Claude to analyze the system and reconstruct its architecture, list of hardware components, dependencies on suppliers, and specifications of the product that had not yet been released. The attackers were particularly interested in military drone control systems and firmware related to artificial intelligence and computer vision.

To gain indirect access to their targets, the group also compromised at least three hotel Wi-Fi providers. After gaining access to administrative accounts, the attackers modified DNS records and redirected user traffic to their own servers. Among the people they attempted to track in this way were individuals with ties to Ukraine, including government officials and drone manufacturers.

In addition, the group attempted to gain access to WhatsApp accounts. According to Anthropic, at least two former high-ranking Ukrainian officials were targeted in such attacks. The attackers used automated browsers to register the compromised accounts as additional devices and export chat history in Ukrainian and Russian on a massive scale.

Anthropic notes that the use of AI is changing the approach to cyber operations: instead of using separate tools for each stage of an attack, attackers can automate entire chains of actions. The company blocked accounts linked to the operations, strengthened its detection systems, and shared the relevant information with partners and law enforcement agencies.

In mid-July, it was reported that An AI model attack on the open-source platform Hugging Face . In August, OpenAI acknowledged that the AI models behind the attack had begun communicate with one another and coordinated their actions to move beyond the test environment.

In early September, it was reported that OpenAI's AI agents have gotten out of control and hacked a German website.

Infrastructure of the future. How EGAP Program builds a digital education ecosystem in Ukraine

Extracted Entities

Attack Types (2)

Companies (1)

Countries (1)

Domains (1)

Industries (1)

MITRE ATT&CK (1)