Anthropic releases 154-page threat intelligence report on Yemen missiles, Iran surveillance, China distillation
Anthropic published its September 2026 threat intelligence report on September 10, detailing Houthi use of Claude as a software engineer for missile guidance, Iranian domestic surveillance, and distillation by seven Chinese labs.
On September 10, Anthropic released its 154-page "Detecting and countering misuse of AI: September 2026" threat intelligence report covering activity disrupted between December 2025 and August 2026 across seven harm categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit model distillation.
The most prominent case involves a weapons development cell operating in northern Yemen that Anthropic assesses is highly likely Houthi-linked. The cell used Claude Code in place of human software engineers, running multiple Claude instances simultaneously and assigning them software development, research, and code review roles. Work covered guidance, navigation, and control software for guided rockets, multi-stage ballistic missiles with stated range goals exceeding 2,000 km, and a separate missile family including a proposed hypersonic glide vehicle. Anthropic said the group test-fired a guided rocket that apparently failed, then returned to Claude to diagnose the failure. The company did not publicly name the operators as Houthis but said accounts were banned and intelligence shared with public and private partners.
Iran-linked cases are similarly extensive. One group used Claude to build automated Python pipelines that aggregated publicly available U.S. naval ship and aircraft transponder identifiers, personnel names from military photo captions, and commercial satellite imagery query scripts to develop targeting recommendations against U.S. naval forces. Another built an identity-record database that surveilled and profiled 6,388 Iranians in a single year and analyzed over 155,000 social media posts to identify 39 opposition and diaspora accounts. Anthropic banned 16 Claude accounts linked to two Iranian paramilitary and domestic security units.
The report also named seven China-based labs involved in distillation campaigns: Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax. The Alibaba-linked campaign was the largest Anthropic measured, with over 151 million exchanges from more than 3,500 fraudulent accounts between May and July 2026, aiming to extract chain-of-thought reasoning from Claude Opus to train Qwen models. A Moonshot-linked campaign generated over 23 million exchanges, with some live Moonshot customer queries silently relayed to Claude. DeepSeek-linked activity produced over 12.1 million exchanges in 14 days, leaking reasoning traces and third-party data.