Iran used American AI to hunt our warships as AI acquisition threats spike

What Anthropic’s September 2026 threat report actually documents — and what it tells us about who else is inside the same door.                                                                                                                                   

By Jeffrey A. Newman Esq. MBA with ai assistance

The Wall Street Journal reported on September 11 that an Iranian-linked group used an American developed artificial intelligence system (Anthropic’s Claude) to build targeting information on United States Navy ships in the Middle East. This according to an Anthropic Report waning of national security threats. Whe WaRobbie Gramer, Michael R. Gordon, and Omar Abdel-Baqui wrote the Wall Street Journal article. .

The underlying Anthropic report is public. It is called Detecting and countering misuse of AI: September 2026, published on September 10 by Anthropic’s Threat Intelligence team. It runs 154 pages and covers activity the company detected and shut down between December 2025 and August 2026. It is free to read. The link is at the end of this article.

The Navy case is one of roughly forty documented in it.

This article explains what the rest of the report says.

On September 8 — two days before this report appeared — we published an examination of how China has been systematically acquiring American AI technology. The report extends that account in two directions. It shows the acquisition has grown substantially larger than was known then. And it shows that acquisition is only one of seven distinct problems — all of them found by a single company looking only at its own systems.

First, the Navy case

An Iran-linked actor used Claude to collect and analyze publicly available information: ship and aircraft transponder signals, military photographs, commercial satellite imagery, and social media. The output was what the report calls targeting books — documents identifying and tracking U.S. naval positions from open-source material.

The actor also directed the AI to compile vulnerability research on shipboard systems, including a catalog of known security flaws in maritime satellite communication terminals.

CBS News reports that the same account additionally designed software for a domestic mass-surveillance platform for Iranian state systems.

Anthropic banned the account, built new detections, and shared intelligence with government authorities.

Two things must be said plainly. First, no classified information was involved. Every input was publicly available. What the AI provided was speed and synthesis — the ability to fuse scattered public data into an intelligence product in a fraction of the time a human team would need.

Second, the report states that it is unclear whether any intelligence generated this way was used in a specific Iranian military operation. That qualifier is Anthropic’s, and it belongs in any honest account.

The disclosure arrived during a period in which Iranian forces have targeted U.S. naval assets in the Gulf region. The report does not establish whether those facts are connected, and this article does not assert that they are.

The seven problems

The report organizes its findings into seven categories of harm. Taken together they describe something broader than any single case.

1. Weapons development

Beyond the Navy case, the report documents a cell based in Yemen that used Claude to integrate flight software onto a phone-class computer and to conduct post-launch analysis involving a tactical guided rocket.

A separate group worked on autonomous drone systems: fault-tolerant control logic and vision guidance for first-person-view drones, with target classification trained on combat footage from Ukraine.

The report also describes a China-based actor that used Claude to prepare a briefing on U.S. Navy anti-torpedo defense systems, assembled from open-source reporting.

Iran-linked activity in this category extended past the naval case into weapons engineering, electronic warfare, and military procurement analysis.

2. Biological research

Anthropic disclosed five cases in which users attempted to direct Claude toward biological work that could support weapons development. The company says this is the first time a private AI firm has published findings of this kind.

The clearest case occurred in May 2026. A user asked Claude to help draft a scientific grant application for gain-of-function research on chikungunya virus — specifically, work to increase the virus’s transmissibility and its ability to evade the human immune system. The application described the researchers as civilian. The work was linked to a military research institute. Anthropic’s biological safety classifier blocked the request.

The other four involved mammalian adaptation of highly pathogenic avian influenza, orthopoxvirus research, toxin optimization, and computational redesign of toxins.

Anthropic was careful about what it could and could not determine. In several cases the company could not confirm whether the underlying work was legitimate science or something else. Gain-of-function research has real medical applications, including vaccine development. The company acted on the combination of method and context rather than on proven intent.

Outside experts have offered useful correctives. Kevin Esvelt, a biosecurity researcher, told one interviewer that none of the five cases registers on his own ranking of threats apart from the likely intent behind them. Doni Bloomfield, a Fordham law professor working on AI and biosecurity, noted that it is not clear how much the models could actually have delivered.

But the report contains one statement that outweighs all five cases. Anthropic said it can no longer assume that its newer models fall safely below the capability threshold at which a model could meaningfully assist someone attempting to develop biological weapons. It says it has responded by restricting a wide range of dual-use biological queries on its most capable models.

That is the first time a major American AI company has said that in public.

3. Espionage against the United States and its allies

The report documents a Russian espionage operation, GTG-20006, whose tradecraft Anthropic assesses as consistent with public reporting on the group known as Midnight Blizzard.

The operation’s most significant innovation was defensive. The actor built AI workflows that monitored whether its own malware had been detected by commercial security products. When a detection occurred, AI agents automatically rewrote and rebuilt the malware until it was no longer detected, then redeployed it. Anthropic’s assessment is that this inverts the economics of cyber defense: a new detection signature, which used to impose real cost on an attacker, can now be routed around faster than defenders can publish it.

The operation touched more than twenty organizations — government ministries, defense and intelligence bodies, embassies, think tanks, and defense-industrial companies, concentrated in Ukraine and Europe.

Among the thefts: the complete proprietary software development kit for a military drone vision system. The actor spent several days reverse-engineering it, recovering the product architecture, the hardware bill of materials, the supplier dependencies, and details of an unannounced product.

To reach travelers, the actor compromised three hospitality vendors that operate hotel guest WiFi and redirected DNS so that guests connecting to hotel networks were served malware. From a North African government technology authority it exfiltrated a credential database containing more than 300,000 national identity records and commercial registry data on more than half a million companies.

A separate operation, GTG-10007, was run by Chinese-speaking operators the report places in Changsha, Hunan province. Two of them were identified as undergraduate students at a Hunan university studying in a School of Computer and Communication Engineering. One had interned at a Chinese security company and was interviewing at another for an offensive cyber operations role.

They targeted roughly fifty organizations globally across education, retail, energy, technology, healthcare, finance, manufacturing, and government.

They ran an autonomous vulnerability research program — an exploit foundry — that loaded vendor firmware into a decompiler, formed hypotheses about weaknesses, wrote exploit code, tested it against lab copies, and iterated until it worked. One workflow running continuously against network appliances produced more than a dozen possible previously-unknown vulnerabilities in a single month.

They also operated a fleet of thirteen standing collection agents on a scheduled job, harvesting content from target websites including publicly accessible U.S. military and government sites such as contract postings, then summarizing and scoring the results in an intelligence-report format for delivery to a distribution portal.

One detail deserves attention. Despite running these workflows against targets worldwide, the operators concentrated their hands-on intrusions exclusively on domestic Chinese victims.

4. The theft of access itself

This finding received almost no press coverage and may matter more than any single case.

Criminal groups have begun treating AI account credentials — API keys and session tokens — as the objective rather than a means. The report explains why. An operator who obtains someone else’s AI credentials gains three things simultaneously: resale value in established criminal markets, free computing power because the attack runs on the victim’s account, and cover, because the activity is attributed to the credential’s legitimate owner.

One French-speaking individual ran a month-long campaign against European political parties, media organizations and think tanks entirely on stolen API keys, rotating them through a proxy layer so the traffic blended with the legitimate owner’s. Across 42 targets he gained internal access to at least 14. He built a doxxing platform, loaded it with tens of millions of records including national health identifiers and material from justice-system breaches, and published it as a dark-web service where people affiliated with a targeted political movement could be looked up by name.

Anthropic’s assessment is that this was one of the clearest cases it has seen of AI-assisted software engineering applied to a mass attack on privacy, and that one person built the entire platform.

A criminal supply chain has formed around this. Groups now run fraudulent websites offering discounted access to frontier AI models. Customers who sign up are silently routed to a different model while the reseller’s software harvests their credentials and sells them onward.

One actor, GTG-50020, attacked roughly thirty AI companies in about four days, using a single working technique repeated across targets. Its stated objective, pursued through more than a dozen avenues, was access to an unreleased Claude model. The report states the actor never obtained it and that every attempted path failed.

Every stolen key described in the report came from Anthropic customers’ environments. The report states that Anthropic’s own systems were not compromised in these cases.

5. Surveillance and political repression

Between January and July 2026, Anthropic disrupted state-aligned, contractor, and commercial surveillance uses of its models.

Several cases involve Chinese security bureaus, which used Claude to compress what would otherwise be analyst work into automated investigative throughput. The subjects included dissidents, Uyghurs who had joined the new Syrian Army, pro-democracy demonstrations in Vancouver, and religious figures across Asia. The dossiers tracked birth dates, travel history, social media activity, and information usable as leverage.

Another case involves what Anthropic assesses to be a municipal cyber police unit running a domestic surveillance system that identified specific Chinese citizens as targets. Targets included pro-democracy figures in Hong Kong, people organizing Tiananmen Square commemorations, advocates for Uyghurs, and Western human rights organizations. One bureau used Claude to draft an internal manual on using AI for surveillance.

Anthropic has separately described accounts linked to Chinese state security organs supporting what the Chinese government terms “stability maintenance.”

Anthropic also describes surveillance work by actors in West Africa, including a consultant working for Malian authorities who used Claude to engineer a mass communications interception platform spanning the country’s mobile operators.

One caution: Anthropic attributes the Uyghurs-in-Syria contractor activity at low confidence. It should be read that way.

6. Elections and information operations

The report documents nine influence operations originating in Russia, Iran, Turkey, the Gulf, South Asia, Africa and Europe, targeting audiences on six continents. The actors include governments, state media, commercial firms selling influence to whoever pays, domestic political operators, and an opposition movement in exile.

Several were timed to national votes.

A Russian state media operation produced fabricated, defamatory claims about Moldova’s president, Maia Sandu, ahead of that country’s September 28, 2025 parliamentary election. In four related cases, individuals used Claude as an editorial production desk for Russian state outlets, including material that reached RT’s English-language broadcast as on-air tickers, captions and voiceover scripts.

An Istanbul-based technology company, BBS Bilisim Teknolojileri, sold access to a platform it marketed in its own documentation as a military-grade, AI-driven, real-time political operations ecosystem. It ingested real census and electoral data and profiled voters constituency by constituency across all 222 Malaysian parliamentary districts, micro-targeting the country’s most sensitive fault lines: race, religion, and royalty. It managed roughly a thousand fake social media accounts and generated fabricated intelligence dossiers containing invented allegations against a named opposition politician.

A France-based digital advertising agency, LKM Company, ran approximately 70 fabricated news websites that published at least 8,913 articles in about 20 languages, amplified by 250 inauthentic commenting accounts. The network shifted political positions depending on who was paying.

In the Central African Republic, a Russian-speaking operator ran a daily content operation through a radio station created and funded by the Wagner Group, feeding fabricated material onto the national broadcaster. He also used Claude to draft employment contracts requiring staff loyalty to the president and to Russia, along with scoring rubrics and a three-strike dismissal process — then used the model to recommend which employees to fire. When Claude flagged the political weighting in the scoring, the operator relabeled it in neutral terms and kept it.

Three Iranian state propaganda institutions — the Islamic Culture and Communications Organization, the Islamic Propaganda Office of Khorasan Razavi, and the Bina Cultural Observatory — used Claude to build campaign doctrine, persona systems and target databases. During the 2026 conflict, one network attributed fabricated claims to CSIS, Brookings and RAND in order to make state messaging appear credible. The same network produced counter-narrative material targeting the Bahá’í, a persecuted religious minority.

One finding cuts against alarm, and should be reported: most of this content drew little or no authentic engagement. Anthropic sits upstream of the platforms and often catches operations while they are still being assembled. The campaigns that reached real audiences were the ones distributed through established state media channels.

7. Illicit distillation

This is the direct continuation of what we published in August.

Distillation is a legitimate and widely used training technique: one model’s outputs are used to train another. What Anthropic calls illicit distillation is covert extraction at industrial scale, conducted without authorization through networks of fraudulent accounts, stolen payment cards, and API keys routed through intermediary services.

Since February 2026, Anthropic says it has disrupted distillation campaigns from seven China-based laboratories. Five are named in this report: Alibaba, Moonshot AI, DeepSeek, Xiaomi, and Zhipu. The combined activity totals roughly 200 million exchanges.

The Alibaba campaign, designated GTG-16005, is described as the largest Anthropic has ever measured. Operators used a fixed prompt designed to make Claude expose its internal reasoning before answering, then converted those transcripts into training data. Volume peaked at nearly three million exchanges in a single day, spread across more than 3,500 fraudulent accounts, totaling more than 151 million exchanges between May and July 2026. Anthropic says the harvested material was used to help train the Qwen 3.5, 3.6 and 3.7 models.

For scale: when Anthropic wrote to the U.S. Senate Committee on Banking, Housing, and Urban Affairs in June 2026 about Alibaba, the figure it cited was 28.8 million exchanges. By September it was 151 million.

The Moonshot AI case, GTG-16002, involves a different method. Anthropic says Moonshot routed some of its own paying customers’ requests to Claude without telling them, then presented Claude’s answers as output from Moonshot’s Kimi models. Over one ten-day period this involved nearly 300,000 customer requests relayed through 5,380 fraudulent accounts. The operation also used a replay technique against Claude’s reasoning signatures to extract thinking traces. Total activity exceeded 23 million exchanges between May and July.

The campaigns targeted specific capabilities: agentic reasoning, software engineering, and logical reasoning.

Qwen is the most downloaded open-model family in the world. In February 2026 the Department of Defense added Alibaba to its list of Chinese military companies.

What the report does not say, and what it cannot

Three limits belong on the record.

This is a vendor-authored document. Anthropic sees only its own platform. It has a commercial interest in the distillation findings, and it wrote to a Senate committee about Alibaba three months before publishing. It did not release a complete victim list, enforcement dates, or the evidence supporting every attribution. Those are real limitations and they should temper how the document is read.

Anthropic disrupted every operation described. That is the company’s central claim and there is no public reason to doubt it.

But disruption is not prevention, and this is the point that matters most.

The Alibaba campaign ran to more than 151 million exchanges before it was stopped. Moonshot’s ran past 23 million. Anthropic’s own finding is that the harvested reasoning was used to train Qwen 3.5, 3.6 and 3.7 — models that have shipped, that are downloadable, and that are now running inside products worldwide.

The ban ended the collection. Nothing in the report establishes that what was already collected was recovered, deleted, or kept out of the training runs. Nothing could. Once reasoning traces are on a server in Hangzhou, an account suspension in San Francisco does not retrieve them.

And the seven labs Anthropic disrupted are the ones Anthropic detected, on Anthropic’s platform. No company has published equivalent findings for the rest of the industry.

What happens if they get the material that actually matters

Everything above involves adversaries using models the companies chose to sell, or extracting behavior through the front door. The harder question is what changes if an adversary obtains the models themselves — the weights, which are the learned parameters that constitute the model’s capability.

Several organizations have addressed this directly, and their conclusions are more pointed than anything in the threat report.

The International AI Safety Report 2026 states the consequence in one line. Stolen weights would pose risks similar to those of openly released models, but without the accompanying protections: “Malicious actors could remove safeguards from the most capable models.”

The reasoning is straightforward. Every safety measure a company builds into a deployed model operates at the point of use. If the model itself is taken, the operator runs it with no restrictions at all. The same report notes that an actor in that position faces none of the reputational, legal, or commercial pressures that currently push frontier developers toward careful deployment.

The same report notes that as of December 2025 there were no confirmed, publicly documented instances of model weight theft. It also notes that research indicates AI data centers may be unable to withstand attacks from the most sophisticated and well-resourced actors.

The RAND Corporation published the standard technical study on this question, Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models. It identifies 38 distinct attack vectors and sorts potential attackers into five levels of operational capacity, from amateurs to highly resourced nation-states. The gap between them is the finding. For a given attack — discovering and exploiting a vulnerability in a model’s machine learning stack — RAND estimates an amateur has less than a 20 percent chance of success and the most capable nation-state has more than an 80 percent chance.

RAND defines five corresponding security levels. Its highest, SL5 — the level intended to stop top-priority operations by the most cyber-capable state institutions — is described in the report as “currently not possible.” RAND states that reaching it would likely require help from the national security community.

Anthropic’s own Responsible Scaling Policy is where this becomes concrete, and it is the document Americans should read alongside the threat report.

Anthropic activated what it calls the ASL-3 Security Standard in May 2025. The standard is designed to make model weight theft substantially harder, and the company has said it expects a higher standard — one that would protect against theft by state-level adversaries — will eventually be required.

The published policy lists who ASL-3 is designed to stop: hacktivists, criminal hacker groups, organized cybercrime, terrorist organizations, corporate espionage teams, internal employees, and state-sponsored programs using broad, untargeted techniques.

It also lists who it is not designed to stop. Explicitly out of scope are “state-sponsored programs that specifically target us” through novel attack chains or insider compromise, along with a small number of non-state actors with state-level resourcing.

Read that against Section 3 of the threat report. The security standard protecting the most capable American AI models is, by the company’s own written definition, not built to stop a determined nation-state that has decided to target it.

Anthropic has been candid about why. In restructuring the policy in February 2026, the company acknowledged that requirements at the higher security levels are very difficult to meet unilaterally, and cited RAND’s assessment that the top level is not currently achievable.

The same revision, according to Anthropic’s changelog, removed the commitment to protect against scaled attacks and distillation attacks from its baseline ASL-2 standard. What practical effect that had, if any, cannot be determined from the public documents, and we make no claim that it had one. The distillation campaigns described in the threat report were detected, disrupted, and disclosed.

None of this is a criticism of Anthropic, which is disclosing considerably more than its competitors and which stopped every operation it describes. It is a description of where the defense line currently sits — and the company drawing that line has said, in writing, where it stops.

What exists in law, and what does not

The final point is the shortest and the one Congress should sit with.

There is no legal requirement that any of this be reported. Anthropic published voluntarily. No statute obligates an AI company to disclose that a foreign state used its product for military targeting, weapons work, or biological research. A company that chose silence would break no law.

There is no federal screening requirement for synthetic DNA. Gene synthesis providers ship ordered genetic sequences to laboratories on request, and no federal law requires them to screen those orders. The Biosecurity Modernization and Innovation Act, introduced in February 2026 by Senators Tom Cotton and Amy Klobuchar, would require screening of orders and customers. It has not passed.

The gain-of-function restriction is narrow. The Department of Health and Human Services banned federally funded high-risk gain-of-function research in July 2026. It takes effect in November and reaches only work the federal government pays for.

The export control tool has not been used. As we reported in August, an interagency committee approved DeepSeek, the memory chipmaker CXMT, and more than a hundred other Chinese companies for addition to the Commerce Department’s Entity List. Those designations were never published. At the time of that reporting, no company had been added to the list since the previous October — the longest gap in more than a decade.

Commercial remedies do not reach the conduct. Distillation has never been litigated by an American AI lab. The International Trade Commission’s exclusion authority does not extend to pure digital transmissions. A contract claim against an offshore entity is worth what a court can collect.

So the current arrangement is this. A private company decides how hard to look, decides what to publish, decides whom to tell, and bears no consequence for choosing otherwise. The detection layer protecting American AI capability is voluntary, privately owned, and — by its own written standard — not calibrated against the adversaries that matter most.

Iran used an American AI to build targeting information on American warships. A company found it, stopped it, told the government, and told the public.

Nothing required any part of that.

Sources

Primary

  • Anthropic Threat Intelligence, Detecting and countering misuse of AI: September 2026 (September 10, 2026): https://www.anthropic.com/threat-intelligence-report-september-2026
  • Full report (PDF): https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
  • Anthropic, Responsible Scaling Policy: https://www.anthropic.com/responsible-scaling-policy
  • Anthropic, Activating AI Safety Level 3 Protections (May 2025): https://www.anthropic.com/activating-asl3-report
  • Anthropic, Responsible Scaling Policy v3 (February 2026): https://www.anthropic.com/news/responsible-scaling-policy-v3
  • RAND Corporation, Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models: https://www.rand.org/pubs/research_reports/RRA2849-1.html
  • International AI Safety Report 2026, Box 3.1, Model weight security: https://arxiv.org/pdf/2602.21012

Reporting

  • Robbie Gramer, Michael R. Gordon and Omar Abdel-Baqui, “Anthropic Says Iran Used Its American AI Model to Target U.S. Navy Warships,” The Wall Street Journal, September 11, 2026
  • Stars and Stripes on the naval targeting case: https://www.stripes.com/branches/navy/2026-09-11/anthropic-ai-navy-middle-east-iran-threat-22818937.html
  • Iran International on the Iranian influence and naval cases: https://www.iranintl.com/en/202609115263
  • CNBC on the Alibaba distillation findings and Anthropic’s letter to the Senate Banking Committee: https://www.cnbc.com/2026/06/24/anthropic-alibaba-distillation-campaign.html
  • Quartz on the five named Chinese laboratories: https://qz.com/anthropic-chinese-ai-labs-distillation-alibaba-deepseek-moonshot-091126
  • Business Standard on the five biological cases: https://www.business-standard.com/world-news/anthropic-blocked-claude-ai-misuse-biological-weapons-research-threat-126091100168_1.html
  • Axios on expert reaction to the biological findings: https://www.axios.com/2026/09/11/ai-warnings-biological-research-dangerous
  • The Spokesman-Review on Anthropic’s biological disclosures and expert commentary: https://www.spokesman.com/stories/2026/sep/10/anthropic-reports-it-blocked-potential-bioweapons-/
  • CBS News on the Iranian account and the biological cases: https://www.cbsnews.com/news/anthropic-ai-claude-biological-weapons-development/
  • This Is Beirut on the Iranian influence operations and the Yemen case: https://thisisbeirut.com.lb/news/politics/anthropic-report-details-iranian-propaganda-operations-and-yemen-missile-development-using-claude
  • TechNode on the report’s stated limitations: https://technode.global/2026/09/11/anthropic-ai-orchestrated-cyberattacks-model-distillation/
  • Reuters, via CNBC, on the unpublished Entity List designations: https://www.cnbc.com/2026/06/17/us-deepseek-blacklist-cxmt-national-security-risks-.html

A note on sourcing. The cyber operations and influence operations sections of the Anthropic report were read in the original document. The surveillance, conventional weapons, biological misuse, and illicit distillation sections were verified against multiple independent news organizations reporting on the same document rather than read in full; those figures are attributed accordingly and are consistent across sources.