Skip to main content

Anthropic Disrupts AI-Assisted Missile Development, Naval Targeting, and Bioweapons Research

11 SEPTEMBER 2026·3 MIN READ·25 SOURCES·Independently corroborated

Anthropic has uncovered widespread misuse of its Claude AI by state-linked actors from Iran, Russia, China, and Yemen, disrupting efforts to develop missile guidance systems, track US warships, and plan bioweapons experiments.

Anthropic Disrupts AI-Assisted Missile Development, Naval Targeting, and Bioweapons Research

Key takeaways · 4

  • 01

    Iran-linked actors used Claude to profile US Navy vessels and research vulnerabilities in shipboard satellite terminals.

  • 02

    A Houthi-linked weapons cell substituted human engineers with Claude Code to write software for guided missiles.

  • 03

    Chinese tech giants launched 190 million illicit distillation attacks to train competing AI models.

  • 04

    Russian cyberespionage groups automated phishing and infrastructure hijacking using multi-agent AI frameworks.

Weaponizing Open-Source Naval Intelligence

An Iran-linked threat actor utilized a Python pipeline built with Claude's assistance to collect and analyze publicly accessible data on United States naval forces operating in the Middle East. [5] The operator compiled targeting handbooks that included a roster of American personnel scraped from public military photograph captions, commercial satellite-imagery query scripts, and transponder identifiers for ships and aircraft. [2][5] The same account directed the artificial intelligence to catalog known software vulnerabilities in shipboard systems, specifically researching flaws in maritime satellite communications terminals, Cisco networking equipment, and industrial control products. [5][9] In separate incidents, an Iran-linked unit based in Qom used Claude to develop domestic surveillance tools, including a malicious Firefox add-on disguised as a prayer-times utility that harvested identities in bulk from social networks. [9]

AI as a Virtual Weapons Engineering Team

In northern Yemen, a weapons engineering cell linked to Houthi operations substituted human software engineers with the Claude Code system across three distinct missile development programs. [8][11] The cell structured its accounts like a virtual engineering team to write missile-guidance software for a tactical rocket, a multi-stage ballistic missile with a range exceeding 2,000 kilometers, and hypersonic glide vehicle designs. [6][8] Operators used the artificial intelligence to adapt open-source autopilot software to a commercial smartphone processor and optimize flight control algorithms. [8] After conducting an unsuccessful live-fire test with a guided rocket, the actors returned to the Claude platform within hours to upload telemetry data and diagnose the malfunction. [8]

Cyberespionage and Pathogen Research

A hacking group utilizing tradecraft consistent with the Russia-based threat actor Midnight Blizzard used Claude to automate phishing, hotel Wi-Fi hijacking, and WhatsApp-takeover operations against the Ukrainian government, military, and diplomatic sectors. [12][16][18] Anthropic also documented five examples of scientists using its models in ways that could support biological weapons development. [14][20] In one case, a researcher located in an unsupported region used virtual private server infrastructure to access Claude and plan avian influenza mammalian-adaptation experiments over several weeks. [14][20] The company banned the accounts involved in these activities and incorporated the findings into its frontier model safeguards. [14][20]

Illicit Distillation and IP Extraction

Chinese artificial intelligence laboratories launched nearly 190 million distillation attacks against Claude between May and July. [1] Operators linked to Alibaba ran the largest illicit distillation operation, producing more than 151 million exchanges that peaked at nearly 3 million per day from over 3,500 fraudulent accounts. [12][16] Distillation involves training smaller models using the outputs of larger, more expensive frontier models to reduce training costs. [1][16] Rather than running bulk queries, DeepSeek and Moonshot AI routed live customer conversations through Claude and used the responses as training data for their own less advanced models. [1][16]

What it means

The 154-page threat intelligence report demonstrates that malicious AI usage is expanding beyond simple chatbot queries into multi-agent frameworks capable of orchestrating complex cyberattacks and substituting for human engineers. Unlike previous theoretical warnings about AI risks, these incidents show hostile actors actively deploying commercial models for tactical military advantages and biological research. The extraction efforts by Chinese firms like Alibaba and DeepSeek also highlight a persistent vulnerability in the frontier model business, where leading platforms inadvertently subsidize the development of their competitors' cheaper alternatives. What the sources don't address: Whether any intelligence or software generated during these operations was successfully deployed in a live military or cyber offensive prior to Anthropic disrupting the accounts.

The documented misuse of frontier models for conventional weapons development, naval targeting, and bioweapons research highlights a critical escalation in adversarial AI operations. It demonstrates that state-linked actors are moving beyond theoretical exploration to actively integrating commercial AI platforms into live military engineering and espionage workflows.

Why it matters
Daily session

Put this to work — one session a day, built for your industry.

Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.

Start free

How this developed

  1. 11 September 2026

    Anthropic Disrupts AI-Assisted Missile Development, Naval Targeting, and Bioweapons Research

  2. 11 September 2026

    Event created from source cluster.

Sources

AI fluency, one session a day, built for your work.