Anthropic says it disrupted an Iran linked actor that used Claude to turn publicly available data into targeting recommendations and handbooks for U.S. The reported activity also included work on a domestic surveillance system and state aligned influence campaigns, underscoring how AI can accelerate research, organi...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What did Anthropic’s 154-page threat-intelligence report reveal about Iran-linked actors using Claude to compile open-source targeting handb. Article summary: Anthropic’s report describes attempted misuse of Claude by Iran-linked, state-aligned, and other actors—not verified operational success. It says the company detected and disrupted the activity, strengthened safeguards, . Topic tags: general, general web, academic. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake num
Anthropic’s September 2026 threat-intelligence report describes how malicious actors allegedly tried to use Claude across seven harm areas between December 2025 and August 2026. Its most consequential Iran-related case involved an account that used the model to collect and analyze public information for targeting recommendations against U.S. naval forces in the Middle East. Anthropic says it disrupted the activity. 15
18
The key distinction matters: the report documents alleged misuse of an AI system to support research and planning. It does not establish that an attack occurred, that Navy systems were compromised, or that the resulting material produced a real-world operational effect.
Anthropic said an Iran-nexus actor used Claude to compile open-source targeting handbooks and track naval positions. Reporting based on the company’s findings says the inputs included personnel names drawn from captions on public military photographs, publicly accessible ship and aircraft transponder identifiers, commercial satellite-imagery query scripts, and websites that exposed naval-movement information. 18
23
26
The actor also reportedly researched potential weaknesses in maritime communications and shipboard systems. That makes the episode an example of AI-assisted intelligence preparation: using a model to aggregate, organize, and analyze information that was already publicly accessible. 20
51
This is not evidence that Claude independently conducted surveillance or enabled an attack. The reported value of the model was speed and synthesis—helping turn disparate public data into structured research and targeting material.
Anthropic also described a separate Iran-linked account that used Claude while developing a domestic surveillance system combining automatic license-plate recognition with mobile-device identifier interception or tracking. 51
The available reporting does not establish whether that platform was deployed, how broadly it operated, who was targeted, or whether it produced surveillance at scale. Those unanswered questions are important: designing or refining a capability is not the same as proving its field use or effectiveness.
The report also identified three Iranian state-aligned influence operations that described their work as “soft war” or “cognitive warfare,” aimed at shaping opinion inside Iran and abroad. Anthropic-linked reporting named the Islamic Culture and Communications Organization, the Islamic Propaganda Office of Khorasan Razavi, and the Bina Cultural Observatory of the Islamic Propaganda Organization. 2
7
According to that reporting, the accounts used Claude for campaign plans, doctrine and planning documents, persona systems, target databases, and multilingual content production. 2
7
A central tactic was attribution laundering: presenting state-backed narratives as though they originated with independent analysts or Western think tanks. The evidence supports the existence of an effort to disguise the origin of content, but it does not demonstrate that the campaigns reached large audiences, changed public opinion, or materially influenced events. 7
Anthropic says its Threat Intelligence team identified and disrupted the operations covered by the report. The company’s report spans cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional-weapons development, and model distillation. 15
38
The report also describes alleged Russian-linked cyber activity against Ukrainian targets, Chinese-linked activity, and a Yemen-based cell’s use of Claude in work related to ballistic-missile guidance. These cases broaden the report’s warning about AI misuse, but the available material does not support firm conclusions about operational success in each case. 4
5
The report’s strongest takeaway is not that AI has replaced traditional intelligence or military operations. It is that capable models can lower the time and organizational burden required to research targets, assemble open-source data, draft code and documents, build surveillance concepts, and produce persuasive content in multiple languages.
For military organizations and other high-value institutions, that raises the practical importance of reducing unnecessary public exposure of personnel, movement, technical, and operational information. For AI providers, it reinforces the need for detection, account enforcement, and threat-intelligence sharing. The cases described by Anthropic show attempted misuse and accelerated workflows—not verified autonomous attacks or demonstrated battlefield outcomes. 15
18
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Anthropic says it disrupted an Iran linked actor that used Claude to turn publicly available data into targeting recommendations and handbooks for U.S.
Anthropic says it disrupted an Iran linked actor that used Claude to turn publicly available data into targeting recommendations and handbooks for U.S. The reported activity also included work on a domestic surveillance system and state aligned influence campaigns, underscoring how AI can accelerate research, organization, multilingual content production, and targeti...