China misused Claude to target dissidents, religious minorities, and journalists—including some who write for “Bitter Winter.”
by Massimo Introvigne

Anthropic has released on September 11 (a significant day as the 25th anniversary of the 9/11 terrorist attack) its most detailed threat‑intelligence report to date, documenting how state and non‑state actors attempted to weaponize its AI model Claude for cyberattacks, influence operations, surveillance, biological misuse, and weapons development. Among the most alarming findings is the systematic misuse of Claude by China‑based actors aligned with the CCP’s security, propaganda, and religious‑affairs apparatus. These operations targeted dissidents, journalists, religious minorities, and diaspora communities worldwide—including journalists who write for “Bitter Winter.”
The report shows that AI has collapsed the traditional gap between sophisticated state‑sponsored operations and lone operators. Offensive capabilities that once required teams of trained cyber specialists can now be executed by individuals using stolen API keys or publicly available multi‑agent frameworks. Anthropic notes that “sophisticated attacks no longer require sophisticated attackers,” and that AI‑enabled kill chains have proliferated across all classes of actors, including state espionage units. China appears prominently among them.
One of the most serious clusters of activity involved a China‑based religious‑affairs intelligence operation targeting Catholic leaders, Tibetan Buddhist civil society, Falun Gong practitioners, and Taiwanese Christian communities. The actors used Claude as a stand‑in for a staffed analyst team, directing it to produce Chinese‑language dossiers, “personnel research drafts,” investigative “clue reports,” and daily “situational awareness” digests. The targeting mirrored precisely the priorities of the CCP’s religious‑affairs bureaucracy and the United Front Work Department. In one case, a user openly identified themselves as an information security officer for the Chinese state.
The actors collected birth dates, birthplaces, immigration histories, and social‑media handles of specific individuals. They mapped religious venues, including floor plans and structural diagrams. They instructed Claude to adopt “China’s standpoint,” label the Tibetan administration in exile as an “illegal separatist administration,” and apply the CCP’s designation of “evil cult” to Falun Gong. The coverage spanned WeChat, Xiaohongshu, Douyin, and Weibo, as well as LinkedIn, Instagram, Threads, X, and Facebook. The daily reporting cycle resembled the workflow of an internal government office.
Another cluster involved China‑based public‑security and state‑security organs using Claude to support “stability maintenance” surveillance and transnational repression. A municipal cyber‑police unit used Claude Code and custom skills to operate a sentiment‑monitoring pipeline, query a government surveillance database, and generate daily reports on politically sensitive incidents. A police academy student used Claude to identify ten private citizens for “control,” including petition interdiction, coercive summonses, and close monitoring of their movements and communications. A local state‑security bureau used Claude to produce daily “situational awareness” briefings formatted according to official templates, profiling overseas activists and requesting pre‑operational venue intelligence for protests abroad, including pro‑democracy marches in Vancouver, Uyghur cultural events in Tūrkiye, and screenings at the Oslo Freedom Forum.

The automated pipeline scraped lists of civil‑society outlets before producing each report, labeling Uyghur advocacy as adjacent to terrorism and major human‑rights organizations as hostile forces. This language is consistent with the CCP’s “three warfares” doctrine—psychological, legal, and public‑opinion warfare.
A third operation involved a China‑based contractor producing automated “public opinion monitoring” briefings for government clients. Claude was instructed to role‑play as a “senior emergency public opinion analyst serving the government of the People’s Republic of China.” The system ingested 15 to 30+ foreign news articles daily from Weibo, X, YouTube, Telegram, and Facebook, scoring content according to political sensitivity and reframing reporting critical of the PRC using mandated terminology. The actor used Claude’s code‑execution environment to run a fully automated document‑generation pipeline. Some documents recommended enforcement actions that only a government could carry out.
Anthropic also identified a PRC government‑aligned operation in Syria that used Claude to track, profile, and recruit Uyghurs and Uyghur armed formations. The armed targets were ethnic Uyghurs who had recently joined the newly formed Syrian Army, units the PRC designates as terrorist organizations. The actor used Claude to identify individuals in Syria assessed to have potential access to those formations and attempted to recruit them by offering payment in exchange for intelligence on the units. In parallel, the actor used Claude to locate Uyghur businesses and points of interest in Syria. This activity took place alongside a broader campaign of surveillance of Uyghur diaspora. Anthropic assesses that the actor was probably a contractor working on behalf of PRC state security rather than a state organ acting directly, but the collection priorities align with those of PRC domestic security.
The report also documents a China‑based actor using Claude to draft a fire‑control specification and acquisition documents for an undersea anti‑torpedo weapons system. The actor produced a 200‑page technical proposal, an executive briefing deck, and benchmarking analyses of U.S. Navy systems. Anthropic assesses that the actor was associated with the Chinese defense industry.
Of particular concern is the section documenting a China‑based campaign targeting Uyghur journalists, including some who also write for “Bitter Winter.” The actor used Claude to structure data scraped from WhatsApp groups and dozens of Telegram channels, creating profiles of individuals deemed vulnerable due to financial stress, family separation, or ideological disillusionment. The actor identified targets with family members in Xinjiang—leverage that only PRC domestic security can exploit. They planned coordinated mass reporting, foreign‑front delegitimization, and bot‑network amplification against journalists from the Uyghur diaspora.
These China‑based operations were not isolated. Anthropic reports parallel campaigns by Russian and Iranian actors, including IRGC‑aligned influence operations and automated disinformation networks. But the Chinese operations stand out for their breadth, bureaucratic structure, and direct alignment with CCP security priorities.
The actor also drafted surveillance‑platform tenders and capability brochures marketed to bureau‑level PRC government clients, suggesting a government client‑to‑vendor operating structure. Claude refused several requests to generate covert interrogation scripts or mass fake personas, but the actor repeatedly attempted to circumvent safeguards.
Anthropic disrupted all operations described in the report. The company emphasizes that the lessons learned have been used to strengthen safeguards and detection systems. Yet the implications are clear. China is not only developing its own AI systems but is actively attempting to weaponize foreign AI models to expand its surveillance, repression, and influence operations.
The report confirms what “Bitter Winter” has documented for years: China’s repression does not stop at its borders. It adapts, evolves, and now leverages frontier AI to extend its reach. The fact that these operations were disrupted is encouraging. The fact that they existed at all is a warning.

Massimo Introvigne (born June 14, 1955 in Rome) is an Italian sociologist of religions. He is the founder and managing director of the Center for Studies on New Religions (CESNUR), an international network of scholars who study new religious movements. Introvigne is the author of some 70 books and more than 100 articles in the field of sociology of religion. He was the main author of the Enciclopedia delle religioni in Italia (Encyclopedia of Religions in Italy). He is a member of the editorial board for the Interdisciplinary Journal of Research on Religion and of the executive board of University of Pennsylvania Press’ Nova Religio. From January 5 to December 31, 2011, he has served as the “Representative on combating racism, xenophobia and discrimination, with a special focus on discrimination against Christians and members of other religions” of the Organization for Security and Co-operation in Europe (OSCE). From 2012 to 2015 he served as chairperson of the Observatory of Religious Liberty, instituted by the Italian Ministry of Foreign Affairs in order to monitor problems of religious liberty on a worldwide scale.


