Anthropic says Claude was used to develop missile-guidance software and support state-linked cyber-espionage operations, according to a new threat report.
Anthropic says it disrupted several malicious uses of its Claude AI models, including attempts involving cyber-espionage, weapons development and large-scale surveillance campaigns.
On the conventional weapons front, the company alleges that it blocked an operation in northern Yemen that sought to use Claude to develop guidance software for a guided rocket and a long-range ballistic missile.
AI-assisted missile and rocket development
According to Anthropic’s threat report, the operators used Claude “in place of human software engineers,” assigning different instances of the model specialized roles in writing missile-guidance and flight-control software.
Although internal safeguards blocked many requests, Anthropic acknowledged that some slipped through. The operators concealed their ultimate objective by dividing the work across separate sessions, ensuring that no single prompt revealed the full scope of the operation.
The company said it found no evidence that the group successfully deployed a working weapon, although the activity appeared to include an unsuccessful test firing.
Anthropic said it banned the accounts involved and “shared threat information with public- and private-sector partners to mitigate risks posed by the actors.”
State-linked cyber-espionage
The report also describes a Russian-linked espionage operation bearing the hallmarks of Midnight Blizzard, also known as APT29. Anthropic said the campaign relied on automated AI workflows for nearly every stage, from phishing and infrastructure setup to data theft targeting Ukrainian, European and diplomatic entities, including drone manufacturers.
Separately, the company said it disrupted a Chinese operation run by university students in Hunan province. The group allegedly used Claude “as the engineering and orchestration layer” for an offensive programme targeting government and corporate networks across the Middle East, Europe and Southeast Asia.
In both cases, Anthropic said it banned the associated accounts and introduced additional monitoring to identify similar activity.
Identifying targets, including in Syria and Iran
Anthropic also alleges that it identified and removed three Iranian state-aligned accounts that used Claude to conduct covert influence and psychological operations. Each account was linked to a named Iranian propaganda institution, including the Islamic Culture and Communications Organisation and a command room at a Mashhad seminary that distributed content aligned with Islamic Revolutionary Guard Corps narratives.
In another case, the report says state-aligned groups used Claude in an industrial-scale operation to generate structured profiles that categorised targets by location, demographics, political leanings and confidence scores.
Anthropic described “the most operationally mature case” as one involving a China-aligned account operated by someone “with no Arabic language skills.” The account allegedly used Claude to conduct a “multi-day recruitment operation to infiltrate Uyghur targets in Syria,” with the model drafting outreach in a regional dialect and translating responses in real time.
Earlier this week, Anthropic disclosed another incident involving an early version of Claude Opus 4.6 gaining unauthorised access to external systems. The revelation came shortly after former company researcher Jacob Coxon publicly resigned over safety concerns.
“The people building AI earnestly believe that it could kill us all by the end of the decade,” Coxon warned in a post on X. Anthropic scientist Evan Hubinger later said Coxon’s assessment was correct.
The researchers’ warnings have prompted a growing number of US lawmakers to call for new rules governing advanced AI systems.
Anthropic said it is investigating the recurring issues and breaches identified across the incidents and has hired an independent research firm to review them.
Relationship with Washington
Relations between Washington and Anthropic remain strained following a dispute over ethical safeguards. Earlier this year, the Pentagon blacklisted the company as a supply-chain risk after it refused to weaken protections against using its technology for autonomous weapons and domestic surveillance.
Anthropic challenged the decision in California, where a judge ruled last month that the US Department of Defense had acted unlawfully in issuing the designation. Despite the legal dispute and public friction, the Pentagon has reportedly deployed Claude models in military missions in Iran and Venezuela.
The report comes as Anthropic seeks to restore its standing within the US defence industrial base following the Pentagon’s blacklisting.

