Vue lecture

Russian spies ran a campaign against Kyiv on Anthropic’s Claude, and the AI chatbot’s maker caught them at it

Illustrative image, photo via Freepik.

A Russian state-linked espionage group ran much of its campaign against Ukraine on Claude, the AI assistant sold by US company Anthropic, which set out the case in a threat report published on 10 September, covering activity it disrupted between December 2025 and August 2026. Ukrainian government, military, and diplomatic staff recurred most often among the targets, with the drone supply chain second. Other Russian users of the same chatbot produced on-air tickers and voiceover scripts for state broadcasters, while Russian-speaking criminals went after the AI industry itself.

Russia's invasion runs on more than troops: the same war that shells Ukrainian cities also targets the networks, newsrooms, and inboxes of those backing Kyiv, pushing European states toward defenses as blunt as quarantining email from Russian domains. 

Ukrainian ministries and diplomats led the target list

Anthropic tracks the group as GTG-20006 and says its attribution matches public reporting that links it to Midnight Blizzard, a hacking group the US and UK governments attribute to Russia's SVR foreign intelligence service. A Russian-speaking operator using the handle JackPoterz ran campaigns against military intelligence targets in Ukrainian and European governments, plus diplomatic and defense bodies and individuals connected to US foreign policy.

More than 20 organizations appeared in the actor's planning and live operations, from ministries and embassies to think tanks and defense companies. Ukrainian government, military, and diplomatic staff came up most often, and the operators scanned email and remote-access systems across more than two dozen Ukrainian state organizations. Russia has worked these networks all war, treating Ukrainian media as a priority cyber target.

europol dismantles pro-russian cyber army flooding ukraine its allies attacks flickr/world's direction crime cyberattack hackers coordinated crackdown wiped out over 100 systems tied kremlin-backed noname057(16) global law enforcement campaign has
Explore further

Ukraine’s media are top Russian cyber target: Hackers hit Ukrainian TV site with 200,000 requests in minute

Drone technology was the other target

The operators bulk-exported the mailboxes of at least two drone component manufacturers and went after a military drone maker. They also stole a complete proprietary software development kit for a drone vision system, the code and documentation engineers need to build on that hardware, then spent days pulling it apart. They recovered the product architecture, the parts list, the supplier dependencies, and details of a product the company had not announced. Military drone control and AI vision firmware drew their particular interest.

Russia's new "Geran-4 Siker" Shahed variant uses machine-vision AI for targeting. Source: Warhronika
Explore further

AI against AI over Ukraine: Russia’s Shahed now sees its target, and Ukraine’s interceptor sees Shahed

To reach people indirectly, the group also compromised at least three vendors running hotel guest WiFi and redirected guests to its own servers, pushing malware at their devices and hunting for Ukrainian officials and drone manufacturers. To reach people indirectly, the group also compromised at least three vendors running hotel guest WiFi and redirected guests to its own servers, pushing malware at their devices and hunting for Ukrainian officials and drone manufacturers. Microsoft documented the same method on 31 July, calling it CaptiveCrunch and tracing it to a Midnight Blizzard sub-cluster. Russian services have tracked the weapons pipeline before, tapping private cameras in Europe to watch arms shipments bound for Ukraine.

What the chatbot did for the operation

Claude fingerprinted mail systems, built the phishing infrastructure, ran commands inside victim networks, harvested credentials, and organized hundreds of gigabytes of stolen data, Anthropic found. Automated agents also checked whether the group's implants were being detected, rewrote flagged malware until it passed, and staged it for the next intrusion. The operators also seized WhatsApp accounts and targeted at least two former high-level Ukrainian officials that way, and stole cloud email from at least eight bodies, including a national prosecutor office and a military education institute.

Russian state media used the same chatbot

Four individual operators fed state outlets, among them a former Sputnik Moldova editor-in-chief. Anthropic says content generated with Claude reached Sputnik Moldova, RIA Novosti, Sputnik en Español, Sputnik Africa, and RT's English newsroom, including fabricated claims about Moldova's President Maia Sandu before the parliamentary election of 28 September 2025. 

A Russian-speaking operator in Bangui also supplied daily material to Radio Lengo Songo, a station investigators say the Wagner Group founded and funded in 2017, coordinating with RT, Sputnik Afrique, and TASS.

Abstract illustration of computer code and binary numbers glowing blue and green against a dark background.
Explore further

Estonia quarantines emails from Russian domains over cyberattack risk

Two crews went after the AI company itself

A Russian-speaking actor moved from hotel-booking and fintech intrusions to attacking AI firms, planting instructions in one vendor's testing system and hitting roughly 30 companies in four days while chasing an unreleased Claude model. The hunt for the model failed, though the actor did take production API keys from that testing system, and Anthropic says its own systems were never breached. A Russian- and Ukrainian-speaking group meanwhile sold fake discounted access to the assistant, routing customers to a different model and stealing their logins.

  •  

The Guardian view on controlling AI: humanity cannot outsource its survival | Editorial

Par : Editorial

Keeping people in charge means little if supercomputers determine the evidence, choices and time on which their decisions depend

If there were a 10% chance that AI could wipe out humanity, no responsible government would leave its development to companies racing to build it. Yet until recently, that seemed to be the case. The warning was all the more ominous because it was made by a researcher at Anthropic, the trillion-dollar AI company behind the Claude chatbot. The dangers of AI-enabled pandemics or attacks on nuclear systems are real. Countries need not agree on democracy or trade policy to accept this.

The US and China will hold, reportedly, their first bilateral AI-safety talks before a planned White House summit between Donald Trump and Xi Jinping. Despite their tech rivalry, neither Washington nor Beijing can make the most advanced AI safe on their own. A US-China settlement won’t be able to say how AI works everywhere. Countries deploying AI must help write the global rulebook. The odds on an extinction event are shortening. This week Anthropic said that it identified five cases in which attempts were made using its models to support biological weapons development. It banned the accounts. In one case, a platform sent requests rejected by Claude to a rival with weaker safeguards. AI safety, clearly, cannot be that of the least responsible model.

Do you have an opinion on the issues raised in this article? If you would like to submit a response of up to 300 words by email to be considered for publication in our letters section, please click here.

Continue reading...

© Photograph: Cinetext Bildarchiv/Mgm/Allstar

© Photograph: Cinetext Bildarchiv/Mgm/Allstar

© Photograph: Cinetext Bildarchiv/Mgm/Allstar

  •  

We have started losing control of AI. It’s time to shut it down | Garrison Lovely

What sounds like the overwrought penultimate episode in a sci-fi series about AI doom is now our reality

On Tuesday, a former OpenAI researcher quit his job at Anthropic, warning that “neither company is acting responsibly” and that “the people building AI earnestly believe that it could kill us all by the end of the decade. This is not a marketing stunt.”

As someone who’s reported on AI risk for years, this wasn’t news to me. But the outpouring of alarm suggests a much wider public is properly confronting this ludicrous situation for the first time.

Continue reading...

© Photograph: Sean Rayford/Getty Images

© Photograph: Sean Rayford/Getty Images

© Photograph: Sean Rayford/Getty Images

  •  

Lawmakers blast AI companies after researcher warns of human extinction by 2030

Par : Dara Kerr

Former Anthropic employee Jacob Coxon said AI will become ‘superhuman systems’ that can cause human extinction by the end of the decade

Just a day after three Anthropic researchers warned that artificial intelligence could kill off humanity within the decade, lawmakers have begun lashing out about the risks of the burgeoning technology.

Ted Cruz, a republican senator from Texas, said in an interview on ABC’s The View, that AI poses a “catastrophic risk” and that he “read that whole tweet thread that that developer put out. It was highly concerning.

Continue reading...

© Photograph: Evelyn Hockstein/Reuters

© Photograph: Evelyn Hockstein/Reuters

© Photograph: Evelyn Hockstein/Reuters

  •  

Anthropic’s Text Watermarking Proves AI Companies Do Not Care at All About Writing

Anthropic’s Text Watermarking Proves AI Companies Do Not Care at All About Writing

Earlier this month, Anthropic announced that future versions of Claude will generate text that includes watermarks showing it was AI-generated. At the time, Anthropic did not explain how this would work, leaving us to speculate on the podcast: Would it somehow encode this into the text? Include invisible characters? Do something with the metadata? We now know, thanks to a blog post over the weekend, that Anthropic will do this by changing how its AI writes altogether. 

“Nothing is added to the text and there are no hidden characters,” Anthropic wrote in that company blog post. “The difference between watermarked and un-watermarked text will not be distinguishable to readers.” The way it will work, the post explained, is that Anthropic will subtly alter the word choices in AI-generated text in a way that is only known to Anthropic and its algorithms. Anthropic will know the watermarking algorithm, which will change “the source of the randomness used to pick among words” and thus can write a tool to detect whether something has been AI-generated.

This research and approach is interesting in a data science kind of way, but Anthropic’s layperson explanation for how this will work shows how little the company thinks about the craft of writing or the subtle differences between words a human author might want to use to convey their thoughts. 

Anthropic asks us to consider the difference between two sentences: “Take the sentence ‘The weather today was cold and…’. The next word is very unlikely to be ‘sugary.’ But it is quite likely to be ‘overcast’ or ‘grey.’ Under most circumstances, it doesn’t matter much to the reader which of these latter two words the model ultimately chooses—the meaning of the sentence is largely the same either way. In cases like this, the choice is settled by a random number,” Anthropic writes. “Watermarking uses low-stakes choices like these—which occur many times over a piece of generated text—to leave a pattern in Claude’s responses. That pattern is undetectable to the reader, but is detectable to anyone who has a key that encodes it. When watermarking is used, choices are still made at random, but the source of the randomness is different.”

Anyone who has written anything would, I hope, understand that the difference between the sentences “The weather today was cold and grey” and “The weather today was cold and overcast” are sometimes “low stakes,” as Anthropic describes, but not always. “Grey,” and “overcast” are different words, and there are any number of reasons why a human author might pick one over the other in a given context. In this example, however, Anthropic’s algorithm sees these words as totally interchangeable and thus its watermarking algorithm has decided that it can “nudge” the word choice one way or the other for the purposes of watermarking. 

Anthropic continues: “Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick. That is, the words that Claude picks are still random, but now, one can check the sequence of words and see if it’s consistent with the choices Claude would make if it was using the key. If it is, one can assign a probability that the text was generated by Claude.”

Anthropic claims “Watermarking does not impact the quality of Claude’s output. To a reader, a watermarked response is indistinguishable from an unwatermarked one,” and that “in internal testing, we’ve seen no impact of watermarking on the content, level of creativity, or readability of Claude’s text.”

People are quite mad about Anthropic’s watermarking system, and understandably so. Synonyms are sometimes interchangeable, but not always, as is pointed out in this excellent essay by John Gruber of Daring Fireball, and by journalism academic Jeff Jarvis, in which he claims Anthropic “devalues writing.” In making this choice, “Anthropic declares words fungible, language random, choice meaningless,” Jarvis writes. 

When I sat down to write this post, I was mad because it seems like Anthropic is  putting its thumb on the scale, messing with the outputs of its machine and saying that the resulting text is qualitatively just the same as the other AI text it was probably going to output. But as I began writing this, I realized that my problem is not necessarily with text watermarking but with AI-generated text altogether. It does not matter to me, necessarily, whether the output of Claude’s garbage AI text is one way or is a slightly different way. But it does matter to me that AI data scientists at huge tech companies think that word choice doesn’t matter, or that it is possible to statistically use synonyms wherever without fucking with the meaning of a sentence.  

Throughout the blog post, Anthropic describes the act of writing as being akin to a probabilistic game of chance. In Anthropic’s own words, its writing is sometimes the result of an “arbitrary random number generator,” and “random” whenever its systems encounter a situation where its tool believes, based on pattern recognition, that the choice between several possible next words isn’t all that important. That may be true for LLM garbage, but is not true for the human experience of writing, which is why human writing almost always feels different than AI writing.

This watermarking approach, and Anthropic’s blog post about it, highlights something that should already be clear about a company that famously scanned and destroyed huge numbers of printed books and has trained its LLMs on stolen content: Anthropic does not care about the craft or effort of writing, and sees words as fungible and unimportant. Anthropic says it is making this change as part of the European Union’s new AI regulations, which are well-intentioned but problematic. While it can definitely be useful to have additional ways of detecting AI-generated content, the carelessness with which Anthropic has announced this decision highlights the broader problem with using LLMs to write: They are, as Anthropic notes, probabilistic tools that do not “write” in the way that humans do, rather, they mimic their training data which is, by definition, things that have already happened and been ingested. 

Contrast this with how Anthropic sees code, something where it says an “exact output is required.” In writing, meanwhile, Anthropic suggests different words are often “equally good.” Over and over again, Anthropic and the researchers who work on this type of watermarking claim that text can be “nudged” in this way without being noticeable to humans or without impacting “quality.” 

But it is worth noting that the people judging the “quality” of the AI-generated outputs are either data scientists or people asking AI tools to do their writing for them, not, say, people who care about reading or writing. The scientific paper that Anthropic cites was done by Google researchers on a Google watermarking tool called “SynthID,” which Anthropic’s watermarking is based on. 

In the SynthID study, quality was assessed by randomly putting watermarking on some Gemini outputs, then asking Gemini users to either thumbs-up or thumbs-down the response: “A random fraction of queries were routed to a watermarked model and an equivalent number to the unwatermarked counterpart. The Gemini user interface allows users to provide feedback on model responses via a thumbs-up (good response) and a thumbs-down (bad response). We analysed approximately 20 million watermarked and unwatermarked responses and computed the thumbs-up and thumbs-down rates (both as a fraction of the total number of thumbs-up and thumbs-down feedback received). We found that the thumbs-up rate for the two models differed by 0.01%.”

I hope it is clear to anyone who has clicked on this article that asking someone who asked a chatbot something to thumbs up or thumbs down a response is not a very good way of assessing the “quality” of “writing.” The other human assessment that Google did was to ask people to assess side-by-side watermarked and unwatermarked text for quality. Here are examples given in an appendix of the study; apparently people did not really have a preference one way or the other:

Anthropic’s Text Watermarking Proves AI Companies Do Not Care at All About Writing

One could argue that these passages are two different ways of explaining something, yes. But they are definitively not the “same,” and it is unclear to any reader why one version is one way and the other version is another way. Why did the LLM write “respiratory failure” in one example and “cessation of breathing” in the other? The answer for both is an “arbitrary random number generator” and proprietary black box algorithmic weighting systems controlled by the AI company. In the watermarked version there’s been an additional “nudging” or messing with the machine that’s already just a pattern matcher. 

The point is, there is no conscious thought or decision-making process happening here, so perhaps watermarked AI text is not all that much more offensive than regular AI text. But to see it laid out in such stark terms by the companies building these machines shows how little they actually care about writing. If you asked me, on the other hand, why I used one word instead of another, I might not be able to tell you exactly why, but I could probably explain to you what I was going for, the style of writing I do, my intended audience, my mood that day, whether my heart was racing or not, where I was, what I was doing, what I did earlier that morning and what I did later that day. Maybe it was a word my third grade teacher used all the time or which I read in an article last week or is an inside joke with my friends or which I have recently become obsessed with or tend to overuse. Why I wrote what I wrote or why I did anything at all is the result of my some mix of human experiences dating back to when I first acquired language as a baby and continuing on to this very moment that I may or may not be able to explain, but which result in a certain style of writing that is mine.

This is the case even when I’m working fast or carelessly dashing off text messages, when the thoughts just kind of flow from my brain to my fingers to my keyboard where I don’t know if what I’m saying is making sense at all but is probably legible because it’s coming from a human brain and not a random number generator. 

This is why short passages of AI-generated text feel soulless and generic, as we have written about repeatedly. And there are many AI tools that use AI to make AI writing seem less generic (yo dawg, we heard you like AI so we put AI in your AI) by using synonyms that are supposed to make a passage sound more human — or less plagiarized — by picking words that are less commonly used. The text outputted by these tools, which are called “spinners” or “humanizers” are often just as uncanny and weird as AI writing itself. Or, when applied to things where, to use Anthropic’s own language, “an exact output is required” such as quotes in a news article, the output is often factually inaccurate, libelous, or just plain garbage.  

  •  

Anthropic payment woes – resolved [en]

[en]

TL;DR: enter card details manually, not using Link, if you need to change your payment method and it’s stuck.

Three days ago my Claude Pro subscription was up for renewal but I’d forgotten to top-up the prepaid credit card I use for this. It was (logically) declined and my subscription was suspended. 

I was using Link as the payment method.

No sweat, I thought, I’ll top up the credit card and “try again”. No luck, still declined. 

Cool cucumber, I’ll just use another card this month. Clicked through to select an other payment method, but… once I was back on the Anthropic payment screen, the active payment method displayed was still the first card that had been declined.

What I did:

What I got:

Then I went a bit wild. I tried to change the payment method again. I went into Link and removed the card, leaving only the second one, but the payment was still attempted by Anthropic (Link?) with the card I had removed 🥴 

I logged out of Link and back in. I even tried Apple Pay. My card transaction statement shows a string of $0 card checks, and my inbox is full of e-mails telling me my payment was unsuccessful, but that is all that there is to show for these efforts. Whatever card I chose, Anthropic insisted on trying the same one again and again.

At some point, inspiration hit and I tried settling the open subscription invoice from inside Link directly, with my other card, instead of through the Anthropic billing screen. That worked! 

But I wasn’t out of the woods. I wanted to buy some extra usage (I know, I know). The same frustrating dance started again, to no avail. 

I decided to let it rest 24 hours and try again.

I tried again today. Same same.

In desperation (of course I’d already had a frustrating chat with Fin the Anthropic “support bot” and sent an e-mail to support) I tried chatting up the Link support chatbot. It confirmed that there was indeed a trace of the failed purchase on their side. At least something! I requested a human, and started chatting up my credit card’s support too, as I now had a clear indication that the purchase request had left Anthropic’s walls.

I’ll spare you the hour of slow, mind-numbing, half-chatbot-half-human support chats. You’ve been there I’m sure. There would be a lot to say.

In the end, after going around in many more circles, here is what worked:

  • I clicked to change the payment method on checkout on the Anthropic site
  • I disconnected Link in there
  • I entered my card details manually

What I did (notice how I’m not signing into Link here):

What I got (notice how this time I actually did manage to get it to switch to the Mastercard and drop the Visa!):

Lo and behold, the payment went through! 

(This is the second card, mind you, I’m not that crazy. Next step, before my next subscription invoice comes around, will be to try and make a purchase with the initial – preferred – card. Maybe by then the e-mail the service cyborg promised with details of why the transaction failed will have reached me.)

Sharing this in hope it can spare at least one other person some headaches.

See on Reddit.

  •  
❌