AI firm Anthropic said an Istanbul-based technology company operated a commercial election-manipulation platform built on its Claude models and used it to target voters in Malaysia, according to its detecting and countering
misuse of the AI report.
Anthropic said it identified and shut down an account linked to the platform, which it described as consisting of roughly 1,000 fake X/Twitter accounts, a fabricated news outlet, and a series of fake intelligence dossiers.
The platform marketed itself as a defensive cyber intelligence and counter-disinformation tool, but Anthropic's investigation found it was in fact sold as a paid "influence-as-a-service" capability.
According to the threat actor's own documentation, the infrastructure was advertised as a "military-grade, AI-driven, real-time political operations ecosystem."
Anthropic said the operation used real census and electoral data, along with millions of voter records, to profile and target Malaysian voters across all 222 parliamentary constituencies, focusing on the country's most sensitive political and social fault lines: race, religion and royalty.
The network of roughly 1,000 fake accounts was designed with "warm-up" logic to appear authentic before deployment, regularly renewing cookies and IP addresses to evade detection.
A dashboard built with Claude Code allowed operators to set how many artificial views each target should receive.
Anthropic said it observed a request for 1 million artificial views in support of the sitting Malaysian prime minister's account, though it noted these figures were self-reported by the actor's own tools and could not be independently verified.
The operation ran a fabricated news outlet called "Malaysia Pulse," feeding it synthetic content through an AI rewriting pipeline, along with an associated YouTube channel whose only video, posted weeks after the channel's creation, featured footage of Malaysian Prime Minister Anwar Ibrahim.
The operators also generated fabricated intelligence dossiers making unsubstantiated allegations against an opposition politician and civil society organizations, claims Anthropic said its own research could find no corroboration for.
Anthropic rated the campaign as "Category Two" on its Breakout Scale, meaning the assets were spread across multiple platforms but showed no evidence of breaking into authentic online communities.
The company said the actor had pursued a contract with Malaysia's national communications regulator, though it found no evidence the pursuit succeeded.
Anthropic said Claude refused or partially refused several of the operation's requests, including after identifying a fabricated dossier as material for political defamation and after balking at language explicitly evoking a psychological operation.
In some cases, the company said, the actor negotiated more sanitized wording with the model to keep building toward the same capability.
Anthropic said it identified the account through internal detection systems and used recovered indicators, including domains, IP addresses, and a GitHub repository, to map the operation's full footprint and disrupt further misuse.
The Malaysia-linked case was one of nine influence operations detailed in Anthropic's report, which covered the period from December 2025 to August 2026 and also included operations originating from Russia, Iran, Gulf countries, South Asia, Africa and Europe.
The broader 154-page report documented a range of alleged misuse of Claude, including a Russian state-linked cyber espionage campaign the company said resembled the group tracked as Midnight Blizzard.
A Yemen-based cell allegedly using Claude Code to help design guidance systems for missile programs, including a long-range ballistic missile and a hypersonic glide vehicle concept; a Russian effort to build autonomous "kamikaze" drone software.
A Mali-linked surveillance system called "Lakana 360" capable of monitoring roughly 25 million mobile subscribers, and a French advertising agency's operation producing thousands of fake news articles across dozens of fabricated websites.
The report also detailed a case in which a user sought help drafting a research funding application aimed at increasing the transmissibility and immune evasion of the chikungunya virus, a request Anthropic said its systems blocked, and disclosed that Chinese AI labs, including Moonshot AI and DeepSeek, had allegedly attempted large-scale extraction of Claude's underlying reasoning processes to train their own models.
Anthropic said that as its models have grown more capable, the technical expertise required to carry out sophisticated cyberattacks has decreased, allowing individuals acting alone to pose threats at a scale that would not have been possible a year earlier.
The company said the cases in the report were not representative of typical misuse but reflected the most notable and novel threat activity it has detected to date, and it called on governments and other AI developers to work toward similar detection and prevention efforts.