Anthropic says it identified and disrupted an Iran-nexus threat actor that used Claude to collect and analyse publicly accessible data in order to develop targeting recommendations against US naval forces in the region, in a case set out in the company's September threat-intelligence report. The actor directed the model to build a Python-based pipeline for open-source intelligence collection and naval position tracking, and assembled the output into what Anthropic describes as "targeting handbooks". The compiled material included a roster of US personnel scraped from captions on public military photographs, publicly accessible ship and aircraft transponder identifiers, commercial satellite-imagery query scripts, and an inventory of public websites that exposed US naval movements. The actor also directed Claude to compile vulnerability research on shipboard systems, including known CVEs affecting maritime VSAT terminals, Cisco communications equipment and industrial control products. Anthropic did not identify the actor or say which ships, bases or operating areas were targeted, and says it banned the account, developed detections and shared threat intelligence with government authorities. The significance is less the collection โ the underlying sources were public โ than the processing: an intelligence product of the kind that previously required a trained analyst team was assembled by a model across dispersed open sources and packaged for use, and the actor's side interest in VSAT, Cisco and ICS CVEs maps the same maritime connectivity stack that navies, ports and commercial shipping all depend on. This is a distinct campaign in the same September report whose Russian espionage cluster and Chinese distillation findings were covered in the 12 September digest.
| Attribute | Detail |
|---|---|
| Sector | Defence |
| Date | 2026-09-13 |
| Source | gCaptain |
| Reliability | Tier 3 |