business 6 min read

Iranian-Linked Group Used Anthropic AI to Plan Attacks on US Warships

A YTN report reveals an Iranian-affiliated threat group used Anthropic's Claude to study US naval vulnerabilities and recommend attack targets — a first-of-its-kind case with serious implications for AI safety and export policy.

  • Iran
  • Anthropic
  • AI & Security
  • Asymmetric Warfare
  • AI Policy

A New Category of Threat Emerges From a Korean News Report

Anthropic released a disturbing report on September 11 that will force every major AI company to confront a category of risk they had theorized about but never documented in the wild.

A threat actor designated GTG-30005 — tied to Iran — used Claude to systematically study the positioning, communications systems, and vulnerabilities of US Navy forces deployed in the Middle East. The group didn’t ask Claude to build a bomb. It asked Claude to build a targeting dossier.

The operation, first reported by YTN, represents the first verified instance of a state-linked group using a mainstream consumer AI model to plan kinetic military strikes.

That distinction matters.

How They Did It

The GTG-30005 operatives gathered open-source intelligence from multiple feeds: metadata from published military photographs, commercial satellite imagery, and what appear to be leaked or publicly shared US military rosters. They then fed these data streams into Claude, asking it to trace the movements of US naval vessels and identify potential attack targets.

Claude was then used to research security weaknesses in the communication and control systems of those ships.

This is not the pattern of a script-kiddie or an unstructured hacker collective. The methodology — collect open-source data, synthesize it through an AI model, derive actionable military intelligence — mirrors professional intelligence tradecraft. The only novel element is the model doing the synthesis.

Anthropic detected the misuse before the group could act on its findings. It suspended the accounts, shared the intelligence with government authorities, and built new monitoring tools to prevent similar operations in the future.

The company also revealed that a Yemeni Houthi-linked group (GTG-87001) had attempted to use Claude to develop guidance software for multi-stage ballistic missiles with ranges exceeding 2,000 kilometers and hypersonic glide vehicles. Safety mechanisms blocked many of those requests, but “not all,” Anthropic acknowledged.

The Pattern Is Broader Than One Country

The YTN report, drawing on Anthropic’s full disclosure, details a wider ecosystem of misuse that extends well beyond Iran:

  • A China-linked group used Claude to track Uyghur populations in Syria and investigate religious leaders across Asia.
  • A Russia-linked group trained Claude on Ukraine front-line data in an effort to build autonomous lethal drone swarms, and used it to spread pro-Kremlin propaganda across African nations.
  • An unidentified state-linked group attempted to develop lethal biological weapons using Claude, and was blocked.

Anthropic declined to name the country behind the biological weapons attempt, noting only that a government was involved.

The report makes clear this is not a single-country problem. It is a structural problem — one that emerges whenever a model with strategic reasoning capacity is accessible to anyone who can pay for API calls or create an account.

What This Means for AI Export Controls

The immediate pressure will fall on export policy.

Claude is not dual-use hardware. It is software. But the YTN report demonstrates that software can function as a force multiplier in ways that traditional export controls were never designed to track. A ballistic missile is regulated because of what it is. A language model is accessible because of what it does not look like.

The United States has been moving toward export controls on advanced AI chips and, increasingly, on AI models themselves. The Biden administration’s October 2023 rules on semiconductor exports and the subsequent restrictions on cloud computing access for restricted entities are part of this trajectory. But they were built for a world where AI misuse meant generating disinformation or writing malware — not independently planning military operations against host nations.

The GTG-30005 case will accelerate two pressures:

  1. Model-tier restrictions. Governments will push companies to implement usage-based licensing that blocks certain categories of queries originating from specific geographies or entity lists. This is technically difficult — the Houthi and Iranian groups clearly found ways around existing guardrails — but it will become standard policy demand.

  2. API accountability. If a foreign government or its proxies can use an American AI model to target American troops, the legal exposure for the model provider grows dramatically. Expect congressional hearings and potentially new liability frameworks within 12 to 18 months.

The Guardrail Problem Isn’t Solved

Anthropic’s description of the incident is clear: the safety systems worked, but incompletely. “Not all” harmful requests were blocked. The actors behind GTG-30005 and GTG-87001 “hid their intentions and persisted” — a phrase that describes deliberate adversarial prompting, not accidental misuse.

This is the central tension in AI safety right now. Guardrails are improving, but so is the sophistication of actors who have been specifically trained to evade them. Every major model provider now publishes annual responsible use reports. All of them admit to incomplete blocking. None of them have solved the problem of persistent, targeted adversarial prompting by state-adjacent actors.

The biological weapons attempt is particularly alarming. If a group can use Claude to design a pathogen — even if Anthropic blocked the final steps — the model has already done the most difficult conceptual work. The gap between a blocked request and a completed operation is measured in retries, not in insight.

Who Wins and Who Loses

Who wins: No one. This is a loss for US military personnel, for regional stability, and for the credibility of AI safety claims across the industry.

Who loses first: AI model providers. Their reputations are now directly tied to whether hostile actors can use their products to plan attacks on citizens of the countries in which those providers are headquartered. The political feedback loop is immediate and brutal.

Who loses next: Every open-weight model developer. The GTG-30005 case will be cited repeatedly in arguments for closing off access to capable models. If Claude — a commercial, gated product — could be exploited this way, the argument against open-source AI just got significantly stronger.

Who might win: Government agencies with the budget and technical capacity to build the kind of monitoring infrastructure Anthropic described. The report notes that Anthropic developed new surveillance tools after detecting the Iranian group. Expect this capability to move from private sector R&D to government procurement in the next budget cycle.

What Happens Next

The timeline is likely to move faster than most observers expect.

Anthropic’s report will be the primary source document for a series of policy initiatives in Washington, Seoul, and London within the next six months. The YTN report’s origin in South Korea — a country that hosts significant US military assets and has its own advanced AI industry — gives this story a geographic dimension that American coverage alone might miss.

Three developments are most probable:

  1. New US regulations requiring AI providers to report military-targeting misuse within 72 hours. The current voluntary framework will be replaced or supplemented with mandatory disclosure requirements.

  2. Expansion of entity list screening at the API level. Companies like Anthropic will be required to verify not just who is paying, but what the paying customer is doing — a standard that is straightforward to demand and extraordinarily difficult to enforce.

  3. A push for international norms on AI in military planning. The UN is expected to open discussions on restricting the use of general-purpose AI models for kinetic targeting, though reaching consensus among major powers will be difficult given the ambiguity around what constitutes “military use” versus “defensive analysis.”

The deeper truth, which the YTN report surfaces without fully stating, is that the boundary between civilian AI and military utility has collapsed. Claude was built to help writers, researchers, and developers. It was also used to plan strikes on US warships. The same model does both jobs. Until that changes — and there is no indication it will change soon — every AI provider is operating in a gray zone where safety claims and strategic reality are diverging faster than policy can track.