Iran-Linked Actors Used Anthropic's Claude to Target U.S. Navy
AI company's threat report reveals state-backed groups exploited its model for military targeting, surveillance, and weapons development.

State actors exploit commercial AI for military intelligence
An Iran-linked threat actor used Anthropic's Claude AI model to compile detailed targeting handbooks on U.S. Navy warships operating in the Middle East, according to a threat intelligence report the company released this week.
The actor leveraged Claude to build a Python pipeline that collected and analyzed publicly available information on U.S. naval forces. The compiled intelligence included personnel rosters scraped from captions in public military photographs, ship and aircraft transponder identifiers, commercial satellite-imagery query scripts, and an inventory of public websites exposing U.S. naval movements. The threat actor also directed Claude to research vulnerabilities in shipboard systems, cataloging known software flaws in maritime satellite communications terminals, Cisco communications equipment, and industrial control products.
Anthropic said it banned the account, developed new detection capabilities, and shared threat intelligence with government authorities.
Why it matters
This disclosure marks one of the first documented cases of state-backed actors using frontier AI models for military targeting operations. The incident demonstrates that commercially available AI systems can be weaponized to aggregate open-source intelligence at scale, even when individual data points seem innocuous. For defense and intelligence communities, it signals that adversaries are already integrating AI into operational workflows—and that guardrails on commercial models remain porous enough to enable sophisticated misuse.
Broader pattern of state-backed AI exploitation
The naval targeting operation appeared alongside other Iran-linked cases in Anthropic's report. A separate Iranian actor used Claude to build an automated identity-profiling tool targeting hundreds of Israeli government and non-government individuals, and to modify open-source credential-theft malware. A third case involved building domestic surveillance software for use against Iranians inside the country.
The 154-page report covers activity Anthropic detected and disrupted between December 2025 and August 2026 across seven categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation of its AI models.
Global scope of AI-enabled threats
The report details state-linked misuse beyond Iran. A suspected Russian state-linked group consistent with public reporting on the actor known as Midnight Blizzard used Claude to automate cyberattacks against Ukrainian government targets and drone manufacturers. Chinese government-aligned actors used the AI to surveil Uyghur diaspora communities in Syria and build dossiers on religious leaders across Asia. A cell in northern Yemen used Claude to develop guidance software for a multistage ballistic missile and test-fired a guided rocket, returning to Claude within hours to analyze the failure.
Circumventing safeguards
Anthropic acknowledged that its safeguards intercepted a significant portion of documented misuse attempts, though some requests succeeded. Threat actors employed techniques including hiding their goals, fragmenting requests across multiple sessions, and routing traffic through virtual private networks to circumvent geographic access controls.
The disclosure comes as Anthropic faces internal debate about AI safety. Evan Hubinger, a scientist at the company, wrote in a social-media post cited by the Wall Street Journal that he believes Anthropic lacks a viable path to solving alignment before the arrival of superintelligent systems.
Anthropic said it shared findings from each investigation with authorities and industry partners and used the results to strengthen its detection systems.
These details were first reported by AI Watch.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
