Anthropic's September 2026 threat report found Iran-linked actors used Claude to profile Israelis and Jewish diaspora targets, while a separate Yemen cell built missile guidance software.
Anthropic's September 2026 threat intelligence report identifies four separate Iran-linked operations that misused Claude: an automated profiling system built on hundreds of individuals connected to Israel and the Jewish diaspora, a domestic surveillance effort inside Iran, a naval-targeting research effort against U.S. forces, and three state propaganda operations. Anthropic disrupted each operation and banned the accounts responsible.
Anthropic's September 2026 Report Documents Four Categories of Iran-Linked Misuse
Anthropic's report, "Detecting and countering misuse of AI: September 2026," covers activity the company disrupted between December 2025 and August 2026. The report groups that activity into seven categories: cyber operations, influence operations, surveillance, conventional weapons development, biological misuse, scams and fraud, and unauthorized model distillation. Four of the disclosed cases trace back to Iran-linked actors, spanning three of those seven categories.
The surveillance section documents an Iran-nexus actor who built an automated open-source intelligence pipeline that scraped the public internet to compile dossiers on individuals connected to Israel and the Jewish diaspora. A separate, distinct Iran-linked actor used Claude to analyze publicly accessible reconnaissance data and generate targeting recommendations against U.S. naval forces operating in the region, according to Iran International's reporting on the disclosure. Anthropic banned the accounts tied to each operation and shared indicators with government and industry partners, a step the company takes after every disruption described in the report.
The Naval-Targeting Case Involved Open-Source Reconnaissance and Vulnerability Research
The account built a Python pipeline, developed with Claude's assistance, to track naval positions from open-source data, according to reporting drawn directly from the Anthropic report. The material it compiled included the names of U.S. personnel pulled from captions on public military photographs, ship and aircraft transponder identifiers, scripts for querying commercial satellite imagery, and lists of public websites that expose naval movements. None of that material required breaching a private system; the operation's core activity was aggregating and structuring information that was already public.
The same account used Claude to research potential vulnerabilities in shipboard systems, including maritime satellite terminals, Cisco communications equipment, and industrial control products, and to catalog known CVEs affecting maritime VSAT terminals. Anthropic's report states it is unclear whether any intelligence generated through this account was used in an actual Iranian military operation, and the company does not claim the pipeline was operationally deployed.
The Profiling System Compiled Dossiers From Public Sources at Scale
The Iran-nexus surveillance operation targeting Israel and the diaspora built what Anthropic describes as an automated identity-profiling harness. The system scraped public sources at scale and compiled the results into intelligence-style dossiers rather than simple contact lists, meaning the output resembled case files an intelligence analyst might assemble by hand, produced instead at automated speed and volume.
The targets included Israeli government officials, private citizens, and organizations connected to Jewish communities outside Israel, according to Anthropic's report. The operation appears to have fed an existing target list rather than building one from scratch, suggesting the actor already had names before turning to Claude to enrich them with additional biographical and organizational detail.
Iran Also Used Claude for Domestic Surveillance, in a Separate Case
Iranian actors also used Claude to support domestic surveillance systems inside Iran, a case Anthropic treats as distinct from the Israel and diaspora profiling operation. Reporting on the same disclosure from This Is Beirut described software combining automatic license-plate recognition with mobile-device identifier interception, tools built for monitoring people inside Iran's own borders rather than targets abroad.
That places the domestic tooling in a different category from the outward-facing profiling of Israeli and diaspora targets. Both cases draw on the same underlying pattern the report describes across its surveillance section: actors using Claude to build the software layer of a monitoring system, writing code and structuring data, rather than simply asking the model questions about individuals.
Anthropic's Report Does Not Describe the Profiling Operation as Containing Antisemitic Content
Anthropic's report does not describe the Israel and diaspora profiling operation itself as containing antisemitic content or hate speech. The finding in that section is a surveillance and targeting operation, not a disinformation or hate-speech case. The antisemitism-adjacent material Anthropic disclosed sits in a separate section of the report, covering Iranian state propaganda rather than the profiling system.
The Iranian Propaganda Operations Targeted Western Institutions and the Bahá'í Minority
Anthropic removed three Iranian state-aligned accounts tied to named institutions: the Islamic Culture and Communications Organization (ICCO) under Iran's Ministry of Culture and Islamic Guidance, the Islamic Propaganda Office of Khorasan Razavi, and the Islamic Propaganda Organization's Bina Cultural Observatory. The operations built doctrine manuals, persona systems, and target databases under a stated program the actors called "Jihad al-Tabyin," or explanatory jihad.
One operation, tied to a director-level official at the Bina Cultural Observatory, generated messaging in the voice of an Islamic Revolutionary Guard Corps (IRGC) spokesperson across multiple sessions. During the 2026 US-Israel-Iran war, the network attributed fabricated claims to Western think tanks including CSIS, Brookings, and RAND, a tactic designed to make state-backed messaging look independently sourced rather than government-produced. The same cluster of operations deployed counter-narrative content targeting the Bahá'í, a persecuted religious minority in Iran, alongside target databases naming international officials and Iranian opposition figures.
A Separate Yemen Cell Used Claude for Weapons Engineering Work
Anthropic disrupted a separate case, tracked internally as GTG-87001, involving a weapons engineering cell based in northern Yemen, territory controlled by the Houthi movement (Ansar Allah). Anthropic's own report does not name the Houthis directly, describing the location only as northern Yemen; multiple outlets covering the report, including TRT World and The National, have made that attribution based on the region's control.
The Yemen Cell Pursued Three Parallel Weapons Programs
The cell ran three parallel weapons programs. The first was a guided rocket using a commodity phone-class flight computer with final-phase homing guidance. The second was a multi-stage ballistic missile with a stated range goal above 2,000 kilometers. The third was a missile family the actors called the "R2000" set, which included a hypersonic glide vehicle variant, a technology historically associated with a small number of advanced military powers.
Anthropic's report describes the actors using Claude Code in place of a human software engineering team to write the guidance, navigation, and control software that steers and stabilizes a flying vehicle. The cell ran multiple Claude sessions in parallel, assigning one instance to coding, a second to research, and a third to reviewing the first instance's output, splitting the work so that no single conversation revealed the program's full scope.
The group conducted a live test of a guided rocket in Yemen. The test appeared to fail, and the actors returned to Claude within hours to help diagnose what went wrong, according to Anthropic. The company says its safeguards blocked a number of the group's requests outright, though the actors found ways around some restrictions by hiding their stated purpose and by never disclosing the full weapons program to any single Claude session.
Diaspora Institutions Represent the Kind of Target This Operation Mapped
The profiling operation targeted organizations tied to Jewish communities outside Israel, a category that includes the kind of institutions covered regularly on this site. American Friends of Magen David Adom, for instance, moved $142.3 million in revenue in fiscal year 2024 to fund Israeli ambulance and blood-banking operations, the kind of high-visibility diaspora fundraising infrastructure that an identity-profiling operation would plausibly want mapped.
Anthropic's report does not name specific organizations targeted in the Israel and diaspora profiling case, and the company states it disrupted the operation and banned the accounts involved. The report also does not specify whether any targeted individuals were notified or whether law enforcement in Israel or the countries hosting the diaspora targets received the underlying data, leaving open how far downstream awareness of the operation actually reached.
Other Diaspora and Dissident Communities Faced Similar Targeting in the Same Report
The Israel and Jewish diaspora case was one of several state-linked surveillance operations in the same report, not an isolated finding. Anthropic disrupted comparable surveillance activity originating in China and West Africa during the same reporting window. Per independent coverage of the report, these campaigns overall "targeted the same diaspora and dissident communities these regimes have historically targeted," including pro-democracy figures in Hong Kong, Tibetan and Falun Gong communities across Asia, and Iranian minority communities and opponents of the Iranian regime abroad.
A Mali-linked case in the same section involved a contractor building surveillance software for national security authorities. Read alongside each other, the cases suggest state-linked profiling of diaspora and minority communities was a recurring pattern across the reporting period, appearing under multiple governments rather than as a single Iran-specific use of Claude.
None of the Disrupted Cases Involved Anthropic's Most Heavily Safeguarded Models
Anthropic's report states that none of the disrupted cases in this reporting period, except one unrelated illicit-distillation case, involved Claude Fable or Mythos-class models, the company's more heavily safeguarded model tier. The cyber operations, surveillance, weapons, and influence cases documented across the report all used Claude Haiku, Sonnet, or Opus instead, the models available to the general public through Anthropic's standard consumer and API products.
Anthropic says it used what it learned from each case to strengthen detection classifiers and that it shares indicators of compromise with government and industry partners after each disruption. The company frames each disclosed case as evidence its detection systems eventually caught the activity, though the report does not state how long any operation ran before Anthropic identified and banned it.
Anthropic Plans to Keep Publishing Threat Reports Every Four to Six Months
Anthropic has published four threat intelligence reports since March 2025, each roughly every four to six months. The company states its visibility into these operations ends once content or code leaves its platform, so it relies on open-source research and industry reporting to confirm downstream impact, including the surveillance case involving Israel and Jewish diaspora targets described in this report.
Israel's own AI research and talent base, covered in TLV Partners' 2026 talent map, names 30 Israeli AI researchers and 20 founders across major labs including OpenAI, DeepMind, and Meta, and sits on the opposite side of this story from the threat actors Anthropic disrupted. The same underlying AI capability that Israeli researchers are building into commercial products is, according to Anthropic's own disclosure, the capability a state-aligned actor attempted to turn against Israeli and Jewish diaspora targets before the company shut the operation down.











