U.S. Central Command (CENTCOM) forces began setting conditions for clearing mines in the Strait of Hormuz, April 11, as two U.S. Navy guided-missile destroyers conducted operations

U.S. Central Command (CENTCOM) forces began setting conditions for clearing mines in the Strait of Hormuz, April 11, as two U.S. Navy guided-missile destroyers conducted operations. U.S. Central Command Photo

Anthropic Says Iran-Linked Actor Used Claude to Compile U.S. Navy Targeting Data

Mike Schuler
Total Views: 0
September 11, 2026

Anthropic says it disrupted an Iran-linked user that used its Claude artificial intelligence models to track U.S. naval forces, compile targeting material and research vulnerabilities in shipboard systems.

The activity was disclosed in Anthropic’s latest threat intelligence report, published Thursday, as the company warned that increasingly capable AI systems are moving beyond simple chatbot assistance and being incorporated into more sophisticated cyber and intelligence operations.

“In another investigation, we identified and disrupted an Iran-nexus threat actor that used Claude to collect and analyze publicly accessible data to develop targeting recommendations against US naval forces in the region,” Anthropic said.

According to the company, the actor used Claude to help build a Python-based pipeline for collecting open-source intelligence and identifying and tracking naval positions. Anthropic said the resulting material was assembled into what it described as “targeting handbooks.”

“The compiled material included a roster of US personnel scraped from captions on public military photographs; publicly accessible ship and aircraft transponder identifiers; commercial satellite-imagery query scripts; and an inventory of public websites that exposed US naval movements,” the report said.

The activity also extended into shipboard cybersecurity research.

“The threat actor also directed Claude to compile vulnerability research on shipboard systems,” Anthropic said, including known cybersecurity vulnerabilities, or CVEs, affecting “maritime VSAT terminals, Cisco communications equipment, and industrial control products.”

Anthropic did not identify the actor or say which U.S. Navy ships, bases or operating areas were targeted, describing it only as an “Iran-nexus” threat actor focused on U.S. naval forces in the region.

The case highlights how generative AI can quickly turn scattered, publicly available maritime and military data into a more useful intelligence. Much of the underlying information described by Anthropic was available from open sources, but Claude was used to help automate the collection, analysis and packaging of that material.

The disclosure comes as AI systems are becoming more capable of carrying out complex work with less direct human involvement. Anthropic said elsewhere in the report that it is increasingly seeing AI used not simply to answer questions, but to execute or orchestrate reconnaissance, exploitation and data-exfiltration workflows. In some cases, humans remained primarily responsible for selecting targets and reviewing the results.

Anthropic said that shift is lowering barriers that once separated sophisticated state-backed operations from smaller groups and individual actors. AI is increasingly being used across the cyber “kill chain,” from reconnaissance and software development to exploitation and processing stolen data, allowing attackers to operate faster and across a broader range of targets.

Anthropic said it shut down the activity after identifying it.

“We banned the actor’s account, developed detections to reduce the risk of future misuse, and shared threat intelligence with government authorities to disrupt the threat,” the company said.

The case appears in Anthropic’s September 2026 report on malicious uses of Claude, which covers threat activity the company says it identified and disrupted across cyber operations, surveillance, influence operations, conventional weapons development and other areas.

Back to Main