AI is being used by enemies of the West (Photo illustration by Michael M. Santiago/Getty Images)

Defence Tech

Anthropic finds its chatbot in Iranian ministries and Yemen rockets

5 minutes read

Anthropic has published its most detailed account yet of people trying to misuse Claude, with some surprising protagonists, and of how far some of them got before the company shut the accounts.

The San Francisco firm said on Thursday that between December 2025 and August 2026 its threat team disrupted many attempts to use the model for cyber operations, state propaganda, domestic surveillance, conventional weapons work and research that could support biological weapons.

Anti-western countries such as Iran, Russia and China often appeared in the files.

It said it banned the accounts, tightened filters and, where it judged it useful, passed material to governments and other companies.

The cases, it stressed, are not typical. They are the most sophisticated misuse it is willing to put on paper.

Their post on X sharing the paper garnered 18 million views within hours.

Anthropic says Iranian state propaganda bodies used Claude to plan what they called “soft war”: Campaign doctrine, fake personas, target lists and copy in half a dozen languages.

The accounts were tied to the Islamic Culture and Communications Organisation, a “cognitive warfare” room run from a Mashhad seminary, and the Bina Cultural Observatory.

One brief included material for the Supreme Leader’s funeral. Another asked the model to write in the voice of an IRGC spokesman during this year’s fighting with Israel and the United States, and to dress official lines up as analysis from CSIS, Brookings and RAND.

Anthropic says Iranian domestic security units used Claude to help assemble a case-management system, scrape more than 155,000 tweets and profile thousands of Iranians in a year.

One designed a Firefox add-on dressed as a prayer-times tool. Another compiled targeting notes on US Navy ships and crews and sketched a domestic system mixing number-plate cameras with phone interception.

The company says the accounts are gone. It also says some of the tooling had already been built.

One group in northern Yemen used Claude’s coding tool in place of software engineers on three programmes at once.

They used it for a guided rocket, a multi-stage ballistic missile with a stated range above 2,000 kilometres, and a family of designs that included a hypersonic glide variant.

Safeguards blocked many requests but not all. The operators then test-fired a guided rocket, which failed.

Within hours they were back in the chat asking the model to read the telemetry. They had also compiled a simulation toolkit that no longer needed Claude to run.

The company says it has no evidence a working weapon was fielded. It does not name the group. The geography is Houthi-held northern Yemen.

A Russia-linked operation, whose methods Anthropic says match the group Microsoft calls Midnight Blizzard, used multi-agent workflows against Ukrainian, European and diplomatic targets.

One freelance Russian user tried the model on kamikaze drones.

In Bamako, a single consultant assessed as working with Mali’s intelligence service used Claude as the engineering staff for a platform watching some 25 million SIM cards.

Five unnamed scientific cases, the firm says, involved work that could support research on dangerous pathogens.

Chinese labs appear in as industrial copyists.

Anthropic accuses operations linked to Alibaba, Moonshot, DeepSeek and others of hoovering Claude’s reasoning traces at industrial scale, with more than 151 million exchanges in one Alibaba-linked campaign alone, to train their own models.

Moonshot, it claims, silently forwarded some customer queries to Claude and kept the transcripts.

A separate influence case in the same report concerns a commercial network rather than a government ministry.

Anthropic says it removed an account that used Claude to write and rewrite political articles for about 70 fabricated news websites, paired with matching X accounts and more than 250 commenting profiles that used AI-generated photos.

The sites were registered from France in a ten-week stretch in mid-2025 and hosted on shared infrastructure. Anthropic traces the operation to LKM Company, a France-based digital advertising agency, and describes it as influence sold as a service. The editorial line shifted with the client.

Audiences in the United States, Brazil, France and the Democratic Republic of Congo were targeted, and a large share of the early output backed Kinshasa’s position on mineral deals and tension with Rwanda.

Bylines named journalists who did not exist. Real reporting was recast with a political slant, then moved across borders without its original context.

Anthropic counted at least 8,913 articles in about 20 languages, said most of it drew little genuine engagement, and assessed the operation as Category Two on the Brookings breakout scale.

The firm says it found no evidence that a government directed the work and that it closed the account before the network built a real audience.

Anthropic said every operation described in the report was disrupted, that the findings were used to strengthen its safeguards, and that information was shared with authorities and other companies where the firm judged that appropriate.

The report is clearer on the accounts than on what remained after they were closed.

In several cases Anthropic itself notes that work had already moved outside the chat, including compiled tools and, in the Yemen file, a simulation programme that no longer required Claude.

Claude is restricted in countries such as Iran and Russia. Anthropic says the operators reached the models anyway through ordinary workarounds, including VPNs and tasks split across separate sessions so that no single prompt laid out the full objective.

The company says many requests were blocked. It also admitted some were not and bypassed internal safeguards.

EU rules adopted over the past two years classify general-purpose models and set duties on transparency, risk assessment and incident reporting.

Anthropic’s case studies are more specific than most of that legislation. They describe named institutions and unnamed cells using a commercial assistant for propaganda, surveillance, cyber operations and weapons software, and a company responding after the activity was detected.

Key Topics

More like this

Culture war

AI firm Anthropic turns to Christian leaders for advice on AI morality

By Carl Deconinck

Tech

Meta says its AI model went rogue and hacked another company during testing

By Carl Deconinck

Tech

Storm of critique after Anthropic watermarks Claude text worldwide to meet EU AI Act rules

By Carl Deconinck

From the capitals

German MPs order hundreds of iPhones on taxpayers’ expense, many go to family

By Carl Deconinck