Anthropic has confirmed that a group with links to Iran used its Claude AI system to conduct research targeting U.S. Navy vessels, according to a threat intelligence disclosure published by the company. The revelation puts Anthropic alongside other major AI providers that have had to publicly acknowledge their models were exploited for purposes that violate their usage policies.

The activity, which Anthropic detected and disrupted, involved using Claude to gather open-source intelligence on naval assets. The group reportedly queried the model for information about ship locations, military infrastructure, and related operational details. Iran-linked accounts were also found using Claude for propaganda generation alongside the naval targeting research, suggesting the effort was broader than a single-focus operation.

What Anthropic Found

Key Facts

  • An Iran-linked group used Claude to research U.S. Navy ship locations and military assets.
  • The accounts were also engaged in AI-assisted propaganda generation.
  • Anthropic detected the misuse and terminated the accounts involved.
  • The disclosure is part of Anthropic's broader effort to publicly report state-linked AI abuse.
  • This is not the first time a foreign-linked group has been caught misusing Claude for intelligence purposes.

Anthropic did not name the specific group behind the activity but described it as Iran-linked, a term intelligence analysts typically use to indicate either direct state affiliation or actors operating in alignment with Iranian government interests. The company said it identified the accounts through its trust and safety monitoring systems before terminating access. Details on exactly how long the accounts were active before detection have not been disclosed publicly.

"We take seriously any attempt to use Claude for purposes that could threaten national security or violate our usage policies, and we work to detect and stop such activity."Anthropic spokesperson
Claude AI Handboek by Leon Tindemans
Get the Claude AI Handboek
458 pages on getting more out of Claude, by AI expert Leon Tindemans. A printed book, written in Dutch, shipped worldwide with track and trace.
View the book →

A Pattern of State-Linked AI Misuse

This is not an isolated case. Claude was previously implicated in a separate incident involving fake identities and malware distributed through GitHub, pointing to a pattern in which bad actors probe AI systems for operational utility across a range of threat categories. The broader AI industry has seen similar disclosures. OpenAI and Google have both published reports describing state-linked actors from Russia, China, Iran, and North Korea attempting to use large language models for tasks ranging from spear-phishing to translation of sensitive documents.

For Anthropic, the disclosure reflects both the risks that come with deploying capable AI systems at scale and the company's stated commitment to transparency around misuse. Publishing these findings publicly is intended to warn researchers, policymakers, and other AI developers about the specific tactics being used. It also serves as a signal to potential bad actors that the company is actively monitoring for this kind of activity.

The naval targeting case is particularly sensitive given current geopolitical tensions in the Middle East and the ongoing U.S. naval presence in the region. Using an AI assistant to accelerate open-source intelligence gathering is a low-cost, relatively low-skill approach that lowers the barrier for groups that may lack dedicated intelligence infrastructure. Even if the information gathered through Claude was publicly available elsewhere, the model's ability to synthesize and summarize large volumes of data quickly makes it a useful tool for that kind of research.

Questions remain about whether existing safeguards are sufficient to prevent this type of misuse before it occurs, rather than catching it after the fact. Anthropic and its peers have invested heavily in content filtering and policy enforcement, but adversarial users regularly attempt to find gaps. The company has not said whether this incident prompted any specific changes to how Claude handles queries related to military assets or vessel tracking.

As AI models grow more capable, the potential value of exploiting them for intelligence work is likely to increase. How companies like Anthropic respond to that pressure, through technical controls, policy enforcement, and public disclosure, will shape the norms around AI security for years ahead.

Further reading: Learn more about Claude's model family, read our background on Anthropic, or browse the latest Claude AI news.