SAN FRANCISCO, — Anthropic has released a 154-page threat intelligence report detailing multiple cases in which its Claude AI models were used by state-linked groups and other actors for military, intelligence, surveillance, influence and weapons-related activities.
The report, "Anthropic's September 2026 threat intelligence " released on September 10, covers activity that Anthropic said it disrupted between December 2025 and August 2026. The company said the accounts involved were banned, safeguards were strengthened based on the findings, and information was shared with government and industry partners where appropriate. Anthropic described the cases as notable examples of AI misuse rather than typical everyday use.
Among the cases highlighted were Iran-linked operations involving naval targeting and domestic surveillance, Iranian state-aligned influence campaigns, and a weapons-development cell in northern Yemen assessed by Anthropic as highly likely to be linked to the Houthis.
Iran-Linked Group Used Claude for U.S. Naval Targeting
Anthropic identified an Iran-nexus threat actor that used Claude to collect and analyze publicly available information for developing targeting recommendations against U.S. naval forces in the region.
According to the report, the operators built an automated Python pipeline with Claude's assistance. The system brought together information including publicly available ship and aircraft transponder identifiers, names of U.S. personnel taken from captions on military photographs, scripts for querying commercial satellite imagery and websites that track naval movements.
The same account also used Claude to research potential vulnerabilities in shipboard systems. The research included known vulnerabilities affecting maritime VSAT terminals, Cisco communications equipment and industrial control products.
Claude Used in Iranian Domestic Surveillance
Anthropic also identified Claude use connected to domestic surveillance activities in Iran.
The company said it banned 16 Claude accounts linked to two units assessed with high confidence as being associated with Iranian paramilitary and domestic security agencies.
One unit, described in the report as being based in Qom, used Claude as an engineering resource for surveillance-related systems. Operators reported having an identity-record database containing information on Iranian nationals and said they had surveilled and profiled 6,388 Iranians during a single year.
Claude was also used to analyze more than 155,000 social media posts and help identify 39 opposition and diaspora accounts for monitoring.
In another case, Iranian actors used Claude to develop and deploy a malicious Firefox browser extension disguised as a prayer-times utility. The extension was designed to collect user identities from social networks. The information was then used in a broader profiling system.
Anthropic said its safeguards blocked many direct requests involving profiling, although some software-tooling requests were not refused.
Iranian Influence Operations Used Multiple Languages
The report also describes three Iranian state-aligned accounts connected to institutions including the Islamic Culture and Communications Organization, the Islamic Propaganda Office of Khorasan Razavi and the Bina Cultural Observatory.
According to Anthropic, the accounts were involved in "soft war" and "cognitive warfare" activities. Operators used Claude to create fake personas, develop target databases and campaign plans, and produce social-media material in multiple languages.
The planning documents referenced Iran's state doctrine of "Jihad al-Tabyin," or explanatory jihad.
Anthropic said the network distributed material across Iranian platforms including Eitaa, Bale and Rubika, as well as X, Instagram, Telegram, TikTok and YouTube and through cultural-attaché networks.
The report also identified instances in which false claims were attributed to Western research institutions, including CSIS, Brookings and RAND, during the 2026 U.S.-Israel-Iran conflict period.
Funeral and Succession Planning
One account linked to the Islamic Culture and Communications Organization uploaded detailed organizational plans concerning the funeral of Iran's Supreme Leader and succession arrangements.
The report states that Ayatollah Ali Khamenei died in a U.S.-Israeli strike on February 28, 2026, and was buried at the Imam Reza shrine in Mashhad on July 9 following a multi-day state funeral. He was succeeded by his son, Mojtaba Khamenei.
Anthropic said operators also used Claude features to prepare succession-related narratives and, in related work, generate messaging in the official voice of an Islamic Revolutionary Guard Corps spokesperson.
Yemen Weapons Cell Used Claude for Weapons Software
A separate case involved a weapons engineering cell operating in northern Yemen that Anthropic assessed as highly likely to be Houthi-linked, although Anthropic did not publicly identify the group by name.
The cell used Claude Code as a substitute for human software engineers across three weapons-development programs between December 2025 and August 2026.
The programs involved a tactical guided rocket using a commodity phone-class flight computer and terminal guidance, a multi-stage ballistic missile with a stated range goal of more than 2,000 kilometers, and a group of variants known as "R2000," including a hypersonic glide vehicle variant.
The operators used Claude to work on guidance, navigation and control software. The report says they integrated an open-source autopilot onto a phone-class flight computer, developed control and position-estimation software, conducted flight simulations and tuned flight-control algorithms.
The operators also ran several Claude instances in parallel. One was used for coding, another for research and another for reviewing the work.
The resulting tools were compiled into a standalone offline executable, allowing the group to continue using the software without further access to Claude.
The group subsequently conducted a test launch of a guided rocket in Yemen. Anthropic said the test appeared to have failed. Within hours, the operators returned to Claude to analyze telemetry data and troubleshoot the test failure.
Anthropic said there is no evidence that an operational weapon was successfully deployed, although the offline software toolkit remained available.
Operators Attempted to Bypass Claude Safeguards
Anthropic said its automated safety systems blocked numerous requests connected with the activities described in the report.
The Yemen-based operators attempted to avoid detection by concealing the military purpose of their work and dividing activities among multiple Claude sessions. This allowed individual sessions to handle coding, research or review without necessarily exposing the complete purpose of the project.
Anthropic said the linked accounts were subsequently banned and that relevant threat indicators were shared with international security agencies.
The company has previously described threat intelligence as an important part of its approach to detecting malicious use of Claude and said findings from real-world misuse investigations are used to improve its safeguards.
Part of a Broader AI Misuse Report
The Yemen case was one of six conventional-weapons cases identified in the September report. Anthropic said three were linked to China, two to Russia and one to Yemen.
The wider report also covers cyber operations, surveillance systems, influence campaigns, biological research misuse, scams and fraud, and attempts to illicitly extract capabilities from Claude through model distillation.
Anthropic said it disrupted all of the operations described in the report and used the findings to strengthen its safeguards. The company also said that, where appropriate, it shared information with authorities and other companies.
The cases involving Iran and Yemen illustrate how AI models can be used not only for general information or software development but also as components in larger intelligence, surveillance, influence and weapons-development workflows. Anthropic said it will continue refining its safeguards as model capabilities advance.
——— End of Article ———