Skip to content

Invest2 publishers2 min readPublished

An Iran-linked actor built US Navy targeting handbooks from public data with Claude's help

Anthropic's threat report says the operation pulled transponder identifiers, satellite-imagery scripts and personnel names off captions on public military photographs, and the company banned the account it traced the work to.

The Investor · Invest desk

Illustration accompanying An Iran-linked actor built US Navy targeting handbooks from public data with Claude's help

What happened

  • Anthropic says an Iran-linked threat actor used Claude to compile targeting handbooks on U.S. Navy warships operating in the Middle East, according to a threat intelligence report it published this week.
  • The compiled material ran from a roster of U.S. personnel scraped off captions on public military photographs to commercial satellite-imagery query scripts and an inventory of websites exposing naval movements.
  • The same section describes two further Iran-linked cases: an automated profiling tool aimed at hundreds of Israeli officials and private individuals, and surveillance software for use against Iranians at home.
  • The report runs 154 pages, covers activity detected between December 2025 and August 2026, and sorts it into seven categories including biological misuse and illicit distillation of Anthropic's models.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure The defects listed were already known and sit inside third-party hardware, so the remediation bill lands on the operators of that equipment.
  • capability A model plus a scripted collection pipeline turns scattered open data into one compiled product.
  • decision Anyone underwriting an agentic deployment now has to decide what "a significant portion" of attempts intercepted is worth, because that adjective is the only measure of residual risk on offer.
  • precedent A frontier lab naming Iranian, Russian and Chinese operations it caught on its own model makes that kind of disclosure the baseline its competitors get measured against.

Every item in the compiled inventory existed before the actor opened a session. Transponder identifiers are broadcast, commercial satellite imagery is a purchase, and the personnel roster came off captions attached to public military photographs [3]. The vulnerability work has the same character: the flaws catalogued in maritime satellite communications terminals, Cisco communications equipment and industrial control products were known ones [4]. What Claude added was assembly, plus a Python pipeline it helped write so the collection could run again [2].

The northern Yemen case in the same report shows what that speed buys. A cell there used Claude to develop guidance software for a multistage ballistic missile, test-fired a guided rocket, and was back within hours asking Claude to analyse the failure, the report said [9]. Iran-linked activity accounts for three of the six state-linked operations the report sets out in detail. The other three are the Russian group consistent with public reporting on Midnight Blizzard, the Chinese government-aligned surveillance of Uyghur diaspora communities in Syria, and the Yemen missile cell [1][8].

The remedy is account-level. Anthropic said it banned the account and developed new detections, and that it shared threat intelligence with government authorities and industry partners [5][14]. The same report lists what got past the controls: concealed objectives, requests fragmented across multiple sessions, and traffic routed through VPNs to circumvent geographic access limits [10]. Anthropic said its safeguards intercepted a significant portion of the attempts it documented while some requests succeeded, and put no figure on that portion [11].

The nine months of activity the report covers produced a banned account, a detection update, and disclosures to government [2][5][6]. The framing from inside the company runs larger. Evan Hubinger, a scientist at Anthropic, said in his view the company had no viable path to solving alignment before superintelligent systems arrive [13]. In a social-media post cited by the Wall Street Journal, he wrote: "We really do earnestly believe AI could kill all humans!" [12]

For anyone pricing the risk, the question is whether compilation was the scarce input. If a competent analyst with public sources and a fortnight produces the same handbook, the model provider's marginal contribution to this particular harm is thin. The remediation bill then sits with whoever operates the satellite communications terminals and industrial control products whose known flaws were listed [4]. If compilation was scarce, the same pipeline logic reaches every agentic deployment a buyer is underwriting this year, and VPN routing already defeats an account ban [10]. The published account supports the first reading more than the second, because the actor already had access to all of the collected material [3].

What to watch

  • Whether Anthropic ever attaches a numeric interception rate to the misuse attempts it documents.
  • Whether Cisco or the maritime satellite communications vendors issue advisories tied to the flaws the report says were catalogued.
  • Whether rival labs publish comparable state-actor detection reports covering their own models.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories