Iran Leverages AI to Target US Navy Vessels

A detailed report reveals how state-linked actors used a major AI model to compile tactical data on American naval forces and develop other high-risk capabilities.
Anthropic has disclosed that an Iran-linked threat actor utilized its Claude AI model to create targeting handbooks for U.S. Navy warships operating in the Middle East. The company stated that it successfully disrupted the operation after detecting the systematic collection of sensitive military data through its platform.
According to a threat intelligence report published this week, the actor did not rely on classified leaks but instead aggregated publicly accessible information. This included ship transponder identifiers, satellite imagery scripts, and personnel rosters scraped from public military photos. The resulting dossier provided a comprehensive overview of American naval movements and potential vulnerabilities in shipboard communication systems.
Aggregating public data for tactical advantage
The operation was sophisticated in its use of automation. The threat actor employed a Python pipeline, which Claude helped build, to streamline the collection and analysis of data. This allowed for the rapid cataloging of known software flaws in maritime satellite terminals and industrial control products. The goal was to create a detailed map of U.S. naval capabilities and weaknesses without direct access to classified networks.
This incident is part of a broader pattern of state-linked misuse documented in the 154-page report. It covers activities detected between December 2025 and August 2026. Other cases included an actor building identity-profiling tools for Israeli individuals and another developing domestic surveillance software. The report highlights a significant shift toward using generative AI to lower the barrier for complex intelligence gathering.
A wider scope of state-linked misuse
The findings extend beyond naval targeting. A suspected Russian state-linked group used the AI to automate cyberattacks against Ukrainian government targets and drone manufacturers. Meanwhile, Chinese-aligned actors leveraged the model to surveil Uyghur diaspora communities and build dossiers on religious leaders across Asia. These examples illustrate the diverse and often hidden ways state actors are integrating AI into their operational toolkits.
One of the most alarming details involved a cell in northern Yemen. They used the AI to develop guidance software for a multistage ballistic missile. After test-firing a guided rocket, they returned to the model within hours to analyze the failure and refine the code. This demonstrates the speed at which AI can assist in the iterative development of conventional weapons systems.
Challenges in securing AI platforms
Anthropic acknowledges that while its safeguards intercepted many attempts, some requests still succeeded. Threat actors employed various techniques to circumvent controls, such as hiding their true goals, fragmenting requests across multiple sessions, and using virtual private networks to bypass geographic restrictions. The company has since banned the associated accounts and shared intelligence with government authorities to strengthen detection systems.
The incident underscores the tension between the utility of large language models and their potential for misuse. As AI capabilities grow, the risk of them being repurposed for harmful ends becomes a critical concern for both tech companies and national security agencies. The trade-off remains clear: open access to powerful tools facilitates innovation but also provides a pathway for adversarial actors to accelerate their campaigns.






