An Iran-Linked Account Used Claude to Build 'Targeting Handbooks' on U.S. Navy Ships, Scraping Sailors' Names From Photo Captions and Cataloging Flaws in Shipboard Satellite Terminals.
Anthropic's September threat report says the same account designed a domestic mass-surveillance platform for Iranian state systems. The company banned it, built new detections and handed the intelligence to U.S. authorities. The report also flags five cases where working scientists used Claude in ways that could support bioweapons development.
Somewhere between December 2025 and August 2026, while American warships were operating against Iran in the Gulf and the Arabian Sea, an account Anthropic links to Iran was using the company's Claude models to assemble what the firm calls "targeting handbooks" on U.S. naval forces in the region. The disclosure is buried in the middle of Anthropic's September threat report, a lengthy accounting of what the company describes as "the most notable and novel threat activity" it has detected and disrupted over the past eight months.
The handbooks were built from open sources, but the assembly was industrial. According to the report and to reporting by Navy Times and gCaptain, the actor had Claude help write a Python pipeline that collected and analyzed publicly available data on U.S. naval movements. The output included a roster of U.S. service members scraped from the captions of public military photographs, ship and aircraft transponder identifiers, scripts for querying commercial satellite imagery by location, and an inventory of websites that expose naval positions. Claude was then asked to use that material to "make targeting recommendations."
The account did not stop at locating ships. It directed the model to compile vulnerability research on shipboard systems, cataloging known software flaws in maritime VSAT satellite communications terminals, Cisco communications equipment and industrial control products of the kind that run a modern warship's machinery. The same account, Anthropic said, designed software for a domestic mass-surveillance platform intended for Iranian state systems.
"We banned the actor's account, developed detections to reduce the risk of future misuse, and shared threat intelligence with government authorities," the company said. It did not say which agencies received the material or whether any of the compiled data was ever used operationally. The Navy has not commented publicly.
The Iranian naval case sits alongside a string of others. Anthropic said it removed three Iranian state-aligned accounts running influence operations, each working for or on behalf of a state propaganda institution, that used Claude to generate content, disguise it as independent news and push it across X, Instagram and TikTok. In China, three accounts tied to a municipal state security service used the model for surveillance and what the company called transnational repression, including a bureau that profiles overseas activists. A Yemeni cell, according to Navy Times, used Claude to develop targeting software for guided missiles. In several cases, Anthropic said, the AI was being used "in place of an engineering workforce."
The part of the report CBS News led with is the biological one. Anthropic identified five cases in which working scientists used Claude "in ways that could support biological weapons development." The company chose not to name them and said it cannot "assert that they intended harm," noting that "the same information that can be used to develop a biological weapon could also be used to develop, for example, a vaccine or a cure for a disease." It called biological misuse "one of the most serious risks of frontier AI models" and said its newest model, Claude Fable 5, now restricts "a wide range of dual-use biological research queries." Separately, the Associated Press reported that after Claude blocked one set of virus-alteration requests, the researchers simply moved to a rival model with weaker safeguards.
The report arrives at an awkward moment for Anthropic's relationship with the U.S. military. The Pentagon cut ties with the company earlier this year after it declined terms that would have allowed Claude to be used for mass surveillance and fully autonomous weapons, and an internal memo ordered commanders to strip the technology from key systems. Yet U.S. forces reportedly continued to use the model in the Iran campaign, and the NSA still runs it internally. The company's own report now shows the adversary was using it too, and that the most effective safeguard available was a human analyst noticing and pulling the plug.
Originally reported by CBS News.