Anthropic Discloses State-Linked Actors Used Claude AI for Military Targeting and Reconnaissance

Anthropic said the Iran-linked actor built a Python pipeline with Claude to automate the production of targeting handbooks and the tracking of naval positions from open-source information.
The reported vulnerability research included known CVEs affecting maritime VSAT terminals, Cisco communications equipment and industrial-control products.
The Iranian attacks referenced in the coverage included ballistic-missile strikes on the USS Delbert D. Black and USS John Paul Jones, while Naval Support Activity Bahrain, headquarters of the Fifth Fleet, was also targeted and reportedly damaged; the ships evaded the attacks without casualties.
Anthropic said the malicious campaigns used multi-agent frameworks capable of reconnaissance, exploitation and data exfiltration. It specifically linked one operation to Russia-based Midnight Blizzard and said Chinese organizations associated with Alibaba, DeepSeek, Xiaomi and Moonshot were among seven labs involved in illicit attempts to distill Claude’s capabilities.
Anthropic identified its two most advanced models as Fable and Mythos, saying none of the reported military-misuse cases involved either model.
Anthropic said an Iran-linked group used its Claude AI model to gather public information on U.S. Navy assets in the Middle East and build targeting handbooks. Crypto Briefing reported that the group combined ship transponder data, military photos, satellite imagery, and naval websites into automated tracking tools. No evidence shows the intelligence directly led to a successful attack, but the disclosure came as Iranian forces struck U.S. warships and a naval facility in Bahrain.
Anthropic also disclosed that groups linked to Iran, Russia, China, and Yemen attempted to use Claude for weapons research, drone swarms, and missile navigation. Bloomberg Law reported that the company disrupted these campaigns and found that Russian-linked operations targeted military groups while Chinese labs tried to copy Claude's capabilities. The company said none of the military misuse cases involved its two most advanced models.
The Iran-linked actor built a Python pipeline that automated intelligence collection using Claude. Crypto Briefing explained that the system pulled data from public ship transponders, military photographs, commercial satellites, and naval tracking websites. Operators then fed this information to Claude to generate handbooks and track vessel positions. The process turned scattered open-source data into actionable military targeting material.
The group also researched known computer vulnerabilities in maritime communications systems and industrial-control equipment. Bloomberg Law reported that the targeted systems included VSAT terminals used on ships, Cisco communications gear, and industrial products. This suggested the effort aimed not just to track assets but to identify ways to disrupt or damage them.
Iran, Russia, China, and Yemen all attempted to misuse Claude for weapons development and military operations. Bloomberg Law reported that these groups sought help with kamikaze drone swarms, missile navigation systems, and biological-weapons research. Anthropic said it identified and disrupted these campaigns before they could access the company's most powerful models, called Fable and Mythos.
Chinese organizations tied to major tech companies including Alibaba, DeepSeek, Xiaomi, and Moonshot attempted to reverse-engineer Claude's capabilities. RFE/RL reported that Anthropic also found Russian-linked operations dubbed Midnight Blizzard targeting military and diplomatic organizations. These efforts revealed a global race to exploit or replicate advanced AI systems for strategic advantage.
The disclosure emerged as Iran escalated military operations against U.S. assets in the Middle East. Yahoo reported that Iranian forces fired ballistic missiles at the USS Delbert D. Black and USS John Paul Jones, while also striking Naval Support Activity Bahrain, home to the Fifth Fleet. Both Navy ships evaded the attacks without casualties, and no evidence links Claude's misuse directly to these strikes.
The timing raises questions about how far the Iran-linked group's intelligence preparation had progressed before Anthropic intervened. RFE/RL noted that Anthropic disrupted Iran's attempts to use AI for propaganda and surveillance of dissidents. The scale of the disclosed abuse suggests organized, sustained effort rather than isolated misuse.
Publishers
25
Articles
19
Reach
44