Anthropic has disclosed several cases in which threat actors allegedly used its Claude AI models for surveillance, influence operations, malware development and conventional weapons research, including activities linked to Iran and a weapons-development cell based in northern Yemen.
The findings were published in Anthropic’s September 2026 Threat Intelligence report, which covers malicious activity identified and disrupted between December 2025 and August 2026. According to the company, the cases involved state-aligned groups, commercial intelligence operators, politically motivated actors and other threat actors attempting to use Claude for activities prohibited under its policies.
Anthropic said it banned accounts connected to the identified operations, strengthened its detection systems and shared relevant intelligence with authorities and industry partners where appropriate.
Iranian-Linked Groups Used Claude for Surveillance
One of the most significant findings involved two linked Iranian units that Anthropic said were associated with paramilitary and domestic security organisations.
The company identified and banned 16 Claude accounts operated by the two units. Although the organisations followed separate operational workflows, Anthropic said they relied on the same central infrastructure for their activities.
According to the investigation, one of the units claimed to maintain an identity database containing information on Iranian nationals and had surveillance and profiling activity involving 6,388 Iranians in a single year.
Claude was used as part of the technical and analytical workflow surrounding this system. The actors used the model to help develop the front end of a surveillance case-management platform and conduct social-network analysis involving 155,216 tweets.
Anthropic said the surveillance infrastructure, referred to as “Arman,” was designed as a centralised case-management system connecting provincial units with central infrastructure.
The system’s subject files could contain information including national identification details, beliefs, criminal records, social-media accounts and an “action” section, according to Anthropic’s investigation.
A Malicious Firefox Extension Was Also Developed
A separate Qom-based provincial unit allegedly used Claude primarily as an engineering tool to develop domestic surveillance capabilities.
Anthropic said the unit created a malicious Firefox browser extension called “al-Najm al-thāqib”, which was deployed to collect user identities from major social-media platforms.
The investigation found that both Iranian units developed browser extensions and interfaces connected to the same Arman infrastructure. Anthropic said Claude was used to provide coding assistance, engineering capabilities and data analysis during the development process.
The company said one unit also used Claude to build or maintain several other tools connected to surveillance operations, including systems intended to resolve identities from phone numbers, analyse Telegram activity and facilitate other forms of digital information gathering.
Anthropic noted that its safeguards rejected explicit requests involving profiling and propaganda, but did not consistently block every request involving surveillance-related software development.
Social Media Data Was Analysed at Large Scale
The Iranian-linked operations also demonstrate how AI can be used to process large amounts of publicly available information.
Anthropic said one actor supplied Claude with large volumes of social-media posts and instructed it to analyse individuals based on characteristics such as demographic information, location and political views.
In the Iranian case involving the 155,216 tweets, the system eventually identified 39 Iranian opposition and diaspora accounts for monitoring, according to Anthropic.
The company said this reflects a wider trend it has observed: AI models are increasingly being used not only to develop surveillance tools, but also to process large datasets and identify individuals considered relevant to an operation.
Another Iranian Operation Focused on Identity Profiling
Anthropic also described a separate Iran-linked actor that used Claude to create an automated open-source intelligence and identity-profiling system.
The operation targeted individuals in Israel and members of the Jewish diaspora. Claude was used to accelerate the collection and analysis of publicly available information and produce intelligence profiles on hundreds of people, according to the report.
The same actor was also involved in malware development and other technical activity, according to Anthropic.
Separately, Anthropic identified Iranian state-system development involving a domestic surveillance platform combining automatic licence-plate recognition with mobile-device identifier interception. The operator also developed analytical tools for examining information from a private Telegram group.
Claude Was Also Used in a Yemen-Based Weapons Programme
Another major case involved a threat-actor cell based in northern Yemen.
Anthropic identified the group under the case designation GTG-87001 and said it was involved in three weapons-development programmes.
The programmes included:
- A guided rocket using a phone-class flight computer and final-phase homing guidance
- A multi-stage ballistic missile with a stated range goal of more than 2,000 kilometres
- A group of missile variants referred to as the “R2000” set, including a hypersonic glide vehicle variant
Anthropic said the actors used Claude Code as part of their engineering workflow to develop guidance, navigation and control software used to steer and stabilise a flying vehicle.
Multiple Claude Sessions Were Used Like an Engineering Team
According to Anthropic, the weapons-development group did not rely on a single AI conversation.
Instead, the actors operated several Claude instances simultaneously and assigned different responsibilities to them.
One instance could be tasked with writing code, another with research and another with reviewing the code produced by the first. Anthropic compared the arrangement to the way a lead engineer might delegate different responsibilities across a small engineering team.
The company said Claude was used to assist with integrating an open-source autopilot onto a phone-class flight computer, developing control and position-estimation software, tuning settings, running firmware builds and conducting flight simulations.
Anthropic did not publish evidence that the group successfully deployed an operational weapon.
However, the company said the actors test-fired a guided rocket, and the test appeared to fail. Within hours, according to Anthropic, they returned to Claude to investigate the reason for the failure.
Safeguards Blocked Some Requests, But Not Everything
Anthropic said its safeguards stopped many of the actors’ requests, but the threat actors attempted several methods to get around those protections.
Among the tactics identified were hiding the actual objective of the work and dividing tasks across multiple sessions so that no individual conversation contained the complete picture of what the actors were attempting to accomplish.
Anthropic said it ultimately identified and banned the account associated with the Yemen operation and introduced additional monitoring designed to detect similar misuse.
The company also noted that the actors had already created an offline simulation toolkit that did not depend on Claude or engineering platforms such as MATLAB.
Anthropic Warns AI Is Becoming Part of Security Operations
The cases involving Iran and Yemen form part of a much broader pattern described in Anthropic’s report.
The company said it is increasingly seeing AI being incorporated directly into operational workflows rather than being used simply as a chatbot or research assistant.
In surveillance cases, Claude was used to develop software, process large datasets, create profiles and support intelligence operations. In the weapons case, it was used as part of an engineering workflow.
Anthropic said this points to a shift in which a single operator can use AI to perform work that would traditionally require a larger team of engineers, analysts or technical specialists.
The company said the report covers seven areas of harmful activity: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and illicit model distillation.
Accounts Were Banned and New Safeguards Added
Anthropic said every operation described in the report involved activity that violated its Usage Policy or terms of service.
After identifying the cases, the company said it banned associated accounts, improved its ability to detect the tactics used by the actors and shared indicators or intelligence with other organisations when appropriate.
The company also acknowledged that increasingly capable AI models create a difficult security challenge: blocking clearly malicious requests is not always enough when users can divide a larger operation into smaller, seemingly ordinary tasks.
Anthropic said its investigations will continue to inform the safeguards used to detect and disrupt similar activity.
The findings highlight a growing concern around advanced AI: the same tools that can help developers, researchers and businesses automate complicated work can also be misused to accelerate surveillance, cyber operations and weapons development. Anthropic’s latest report suggests that monitoring how AI is used in real-world operations is becoming an increasingly important part of AI safety.
(Anthropic Claude, Iran Surveillance, Claude AI Misuse, Yemen Weapons Programme, AI Security, Artificial Intelligence)
