- Iran-linked adversaries used Claude AI to compile open-source data to identify U.S. naval positions and develop targeting recommendations.
- Anthropic banned the account and shared information with the U.S. government to disrupt the threat.
- Anthropic found three Iranian state-aligned accounts using Claude for public influence campaigns.
- Russia used Claude AI for cyber-espionage against Ukrainian and European targets, disinformation in Africa and Moldova, and drone targeting software.
- Anthropic blocked all malicious activity, strengthened security, and shared findings with government bodies and industry partners.
- Access to Claude is blocked in Iran, but adversaries can easily create accounts using VPNs and foreign phone numbers.
- Before Anthropic's report, a July report by threat intelligence provider Recorded Future found that AI likely accelerated Iran's existing cyber and military capabilities.
- Given Russia's support of Iran's military, the report said there is an increased likelihood that AI-enabled tactics and capabilities contributed to Iranian drone attacks against Israel and Persian Gulf states.
Anthropic's report highlights the alarming use of its Claude AI by adversaries linked to Iran and Russia for military and disinformation purposes.5
An Iran-linked group utilized Claude AI to gather open-source intelligence on U.S. naval positions, enhancing their targeting capabilities. "They're using it to enhance the way they already operate," said Nikita Shah from the Center for Strategic and International Studies.12
The report indicates that adversaries can now more easily analyze vast amounts of publicly available data, making it challenging for the U.S. military to maintain operational secrecy.
In a significant case, a hacking group known as GTG-20006, linked to Russia's SVR, employed Claude AI for cyber-espionage against over 20 organizations, primarily targeting Ukraine.

"The new threat is just that it is now easier than ever for adversaries to be able to understand what the U.S. military is doing," stated Sam Bresnick from Georgetown's Center for Security and Emerging Technology.
Anthropic has blocked all identified malicious activities and shared its findings with government bodies to bolster security measures.
The report also details how Iranian state-aligned accounts used Claude for propaganda, while Russian developers created software for kamikaze drones, demonstrating the dual-use nature of AI technologies in modern warfare.
"Because they are aware now that less sophisticated actors can understand what they're doing, we're about to see a great deal of countermeasures to try to reestablish a level of potential surprise," Bresnick added.
“Anthropic identified a hacking group linked to Russia's SVR that used Claude to automate attacks on over 20 organizations, including government ministries and defense firms. The company also shut down a Russia-linked drone project that tested an autonomous targeting system on real hardware.”









