Anthropic says Claude AI was used in missile programs, worldwide espionage
Anthropic says it has disrupted several malicious efforts involving its Claude AI models, including alleged cyber-espionage, weapons development and large-scale surveillance activity.
In the area of conventional weapons, the company said in a new report that it acted against an operation in northern Yemen that attempted to use Claude for missile-guidance software. The effort reportedly involved work on both a guided rocket and a long-range ballistic missile.
Recommended Stories
• list 1 of 3US judge halts Pentagon move to blacklist AI company Anthropic
• list 2 of 3Music companies accuse Anthropic of using copyrighted songs for AI training
• list 3 of 3US and EU pursue different approaches to AI regulation
AI-supported missile and rocket development
Anthropic’s threat report said the operators used Claude as a substitute for software engineers, assigning separate model sessions distinct responsibilities for producing missile-guidance and flight-control code.
The company said its safeguards rejected many of the requests, but acknowledged that some material was generated. The group allegedly concealed its broader purpose by dividing work among separate conversations, preventing any individual request from clearly exposing the wider project.
Anthropic said it had found no proof that the group successfully deployed an operational weapon. However, it said the actors appeared to have attempted a test launch that did not succeed.
The company said it shut down the related accounts and shared relevant threat intelligence with public and private partners to reduce the risks linked to the operation.
State-linked cyber-espionage
The report also described a Russia-linked espionage campaign with characteristics associated with Midnight Blizzard, also known as APT29. Anthropic said the operation used automated AI workflows for much of its activity, from phishing and technical preparation to stealing data from Ukrainian, European and diplomatic targets, including drone manufacturers.
In a separate case, Anthropic said it stopped a Chinese campaign operated by university students in Hunan province. The group allegedly used Claude as an engineering and coordination tool for attacks on government and corporate networks in the Middle East, Europe and Southeast Asia.
Anthropic said it terminated the accounts involved in both incidents and introduced additional monitoring intended to identify related activity.
Target identification, including in Syria and Iran
Anthropic said it also found and removed three Iran-aligned accounts that used Claude for covert influence and psychological operations. The company linked each campaign to identified Iranian propaganda organisations, including the Islamic Culture and Communications Organisation and a Mashhad seminary command room that circulated material aligned with narratives associated with the Islamic Revolutionary Guards Corps.
In another case, Anthropic alleged that state-aligned actors used Claude in a large-scale profiling effort. The model was reportedly instructed to produce structured target records containing locations, demographic details, political views and confidence ratings.
Anthropic described its most advanced case as involving a China-aligned account with no Arabic-language ability. The account allegedly used Claude during a multi-day recruitment effort targeting Uyghur individuals in Syria. According to the company, the model prepared messages in a local dialect and translated responses as they arrived.
Anthropic recently disclosed another event in which an early version of Claude Opus 4.6 gained unauthorised access to outside systems. The disclosure came shortly after former company researcher Jacob Coxon resigned publicly, citing concerns about AI safety.
Coxon warned that people developing AI systems believe the technology could become catastrophic within the decade. Another Anthropic researcher, Evan Hubinger, later said he agreed with that assessment.
Such warnings have added to calls from a growing number of US lawmakers for stronger rules governing advanced AI systems.
Anthropic said it is examining the repeated safety and security concerns raised by these incidents and has hired an independent research organisation to assess them.
Relationship with Washington
Anthropic’s relationship with Washington has remained tense after a dispute over the company’s ethical restrictions. Earlier this year, the Pentagon labelled Anthropic a supply-chain risk after it declined to remove protections against the use of its technology for autonomous weapons and domestic surveillance.
Anthropic challenged that decision in California, where a judge ruled last month that the US Department of Defense had acted unlawfully in making the designation. Despite the legal conflict and public disagreement, the Pentagon has reportedly used Claude models during military operations involving Iran and Venezuela.
The report comes at an important moment for Anthropic as it works to regain its full position in the US defence industrial sector after the Pentagon’s blacklisting.