← Back to StoryBreak

Anthropic Says Iran-Linked Users Used Claude to Build Targeting Files on U.S. Warships

Anthropic says it disrupted an Iran-linked operation that used Claude to collect public information on U.S. naval forces and turn it into targeting recommendations. The company has not said the operation led to an attack on a U.S. vessel or base.

By StoryBreak

Published September 11, 2026 at 7:21 PM

Anthropic Says Iran-Linked Users Used Claude to Build Targeting Files on U.S. Warships
AI-generated image / StoryBreak

Anthropic says it disrupted an Iran-linked operation that used its Claude AI model to assemble targeting intelligence on U.S. naval forces operating in the region—a disclosure that highlights how quickly artificial intelligence can turn scattered public information into a military planning resource.

According to Anthropic’s September 2026 threat-intelligence report, the actor used Claude to help build a Python-based pipeline for collecting and analyzing open-source information. The resulting “targeting handbooks” reportedly included names of U.S. personnel taken from captions on public military photographs, ship and aircraft transponder identifiers, scripts for querying commercial satellite imagery, and websites that exposed information about naval movements.

Anthropic also said the actor directed Claude to research weaknesses in shipboard systems. That work included cataloging publicly known vulnerabilities in maritime satellite communications terminals, Cisco communications equipment and industrial-control products.

The company said it banned the associated account, developed new detection methods and shared information about the activity with government and private-sector partners. Anthropic did not identify the actor by name or provide evidence in the report that a U.S. ship or naval base was successfully attacked using the material.

That distinction matters. The disclosure describes intelligence collection and analysis—not an autonomous weapons system and not a confirmed strike. The information reportedly came from sources that were already publicly accessible. The role of Claude was to help gather, organize and analyze those sources at greater speed and scale.

That is still a consequential shift. Traditional open-source intelligence work can require analysts to search across photographs, ship-tracking data, satellite-imagery services, technical databases and military websites. An AI-assisted pipeline can help connect those fragments, produce structured dossiers and identify areas for further research. The result may be more useful to a hostile operator even when every individual piece of information was already available to the public.

The naval case was one part of a wider set of Iran-linked activity described by Anthropic. The company said another actor used Claude to build an automated profiling system aimed at hundreds of Israeli government and non-government individuals, as well as people and organizations in the Jewish diaspora. It also described separate efforts involving domestic surveillance software and the modification of open-source credential-theft malware.

Anthropic’s findings should be read with an important limitation: the report is the company’s own account of activity detected on its platform. Independent reports by QZ, Mint and CBS News have corroborated the basic description of the U.S. naval-intelligence operation, but the public evidence still does not establish who ultimately controlled the account, whether the material reached Iranian military planners or whether it affected a real-world operation.

The episode nevertheless points to a broader security problem. AI misuse does not always require secret databases, sophisticated malware or a model that can control weapons directly. A system that can rapidly transform public fragments into a coherent intelligence product may be enough to lower the cost of surveillance and targeting.

The next questions are likely to concern attribution and impact: whether investigators can connect the account to a specific Iranian institution, whether any collected information was used outside the platform and how AI companies can identify users who conceal their intentions by splitting requests across multiple sessions or routing activity through virtual private networks.

Sources & Further Reading

StoryBreak

Independent digital news and reporting, updated throughout the day.

This article was researched and drafted with AI assistance and reviewed as part of StoryBreak's editorial process before publication. Read our editorial standards.