Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

iranintl+1qz+1stripesAnthropic disclosed Thursday that an Iran-linked threat actor used its Claude AI model to compile targeting handbooks on U.S. Navy warships operating in the Middle East, part of a broader pattern of state-aligned misuse detailed in a 154-page threat intelligence report published by the company.
The actor used Claude to collect and analyze publicly accessible data on U.S. naval forces, building what Anthropic described as "targeting books" to identify and track Navy positions through open-source information. The compiled material included names of U.S. personnel scraped from captions on public military photographs, ship and aircraft transponder identifiers, commercial satellite-imagery query scripts, and an inventory of public websites that exposed U.S. naval movements.iranintl+2
The account also directed Claude to research vulnerabilities in shipboard systems, cataloging known software flaws in maritime satellite communications terminals, Cisco communications equipment, and industrial control products. The same account separately used Claude to develop components for an Iranian domestic surveillance platform combining automatic license-plate recognition with interception of mobile-device identifiers.qz+1
Anthropic said it banned the account, developed new detections, and shared threat intelligence with government authorities.stripes
The report, covering activity disrupted between December 2025 and August 2026, also identified three Iranian state-aligned accounts tied to government propaganda institutions, including the Islamic Culture and Communications Organisation under Iran's Ministry of Culture and Islamic Guidance and the Islamic Propaganda Organization's Bina Cultural Observatory. The accounts used Claude to produce campaign plans, persona systems, and target databases, turning official intelligence bulletins into tailored material in Farsi, Arabic, Urdu, and other languages across a plan spanning 20 languages. During the 2026 U.S.-Israel-Iran war, the network attributed false claims to Western research institutions including CSIS, Brookings, and RAND to lend credibility to state-backed messaging.cbsnews+1
Beyond Iran, the report detailed a suspected Russian state-linked group consistent with the actor known as Midnight Blizzard that used Claude to automate cyberattacks against Ukrainian government targets and drone manufacturers, and a Chinese operation run by university students targeting government and corporate networks across the Middle East, Europe, and Southeast Asia. In northern Yemen, operators used Claude to develop guidance software for a ballistic missile and test-fired a guided rocket, returning to Claude within hours to analyze the failure.aljazeera+1
The disclosures arrive as the Navy has already urged personnel to take precautions against potential threats. Acting Navy Secretary Hung Cao said in an Aug. 19 message to the force: "By embracing this heightened posture of vigilance, we will safeguard our force, protect our families, and ensure the unhindered execution of our national security mission".stripes