Invest1 publisher2 min readPublished
Anthropic says Iranian security units used Claude to profile thousands of citizens
Anthropic's own threat reporting describes two separate operations using Claude to profile people connected to Iran, one of them run by paramilitary and security units against thousands of citizens.
The Investor · Invest desk

What happened
- Anthropic reported that Iranian paramilitary and security units used its Claude model to monitor thousands of Iranians and to pinpoint accounts belonging to opposition and diaspora figures.
- A second operation in the same reporting, linked to the Mojahedin-e Khalq, used the model to impersonate activists and gather profiles of individuals inside Iran.
- Cryptobriefing, which carried the report, described the activity as reflecting heightened internal security measures in Iran amid ongoing repression of dissidents and intensified surveillance.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- precedent A vendor naming a state security user of its own model gives buyers and regulators a reference case to cite when they ask any other lab what it detects and what it publishes.
- constraint The public record on Anthropic's controls here is a summary, so a procurement team that wants this incident in a contract discussion has to request the underlying report first.
- exposure Any operator running profiling work through a frontier model is now reachable by the vendor's own threat reporting, whichever side of a political conflict it sits on.
- contradiction The publisher's inference about a sophisticated state intelligence operation travels further than the vendor's finding does, and a reader who treats the two as one claim is relying on cryptobriefing, not on Anthropic.
Monitoring thousands of people and then picking out which accounts belong to opposition and diaspora figures is a classification task, and Anthropic's report puts that task on Claude [1]. The second operation described runs the other direction, impersonating activists to gather profiles of individuals inside Iran, and it is linked to the Mojahedin-e Khalq [2]. Two separate actors, both using the same commercial model against people connected to the same country [7].
The account gives one number: "thousands" of monitored Iranians [1]. Cryptobriefing, which carried the report, does not give the date of Anthropic's findings, the number of accounts suspended, or how the activity was detected [8].
The publisher then packages the finding as a trade. Its summary says "Market pricing suggests an increased likelihood of leadership change scenarios, reflecting concerns about potential instability arising from these repressive actions" [4], and the article closes by inviting readers to "Get live prediction-market analysis, powered by Vera" [5]. A probability claim needs a venue and a quoted level before it is a price, and in my view this one has neither. It is a characterisation of sentiment in promotional copy.
The version of this that would change a vendor review is the full report, with the account counts, the dates and the detection method. If another frontier lab discloses comparable state security use of its own models, publishing this class of finding becomes the expectation, and any lab that stays quiet gets asked why. If nothing else arrives, the incident stays what this account made of it, an input to Iran leadership-change talk [4].
Anthropic found and named users of its own product [1]. Detection worked at some point. A published report would settle how long the two operations ran before it worked; the summary in circulation does not [8].
What to watch
- Publication of Anthropic's underlying report with account counts, dates and the detection method.
- A comparable disclosure from another frontier lab about state security use of its own models.
- Any response from Iranian authorities or from the Mojahedin-e Khalq to being named.