Anthropic announced that accounts attributed to operators linked to Iran have used the 'Cloud' model to automate military and security information gathering, and after identifying patterns of abuse, these accounts were blocked and the company's protective systems were strengthened.
According to the latest threat and abuse reports, the company attributed the origin of these activities to operators linked to Iran and described the use of artificial intelligence tools in the form of several cases. These reports referenced examples such as the use of a malicious browser extension for 'harvesting user identities from social networks'; a method that has been employed as part of data collection tools. This set also explains that a significant portion of these patterns occurred with older versions of the models, and with the imposition of restrictions, some actors have migrated to open-source models.
Company's official statement and delineation of public data
In the reports of September 10-11, 2026, Anthropic, while releasing details related to the identification and counteraction of these accounts, clarified that no public evidence regarding specific targeting—including monitoring of the U.S. fleet or compiling a list of Israeli targets—has been published. As a result, what is available to the public presents a general picture of the use of the model for data analysis and support for surveillance operations, rather than classified documents that could explicitly prove a specific military target.
This delineation between identified findings and the level of public disclosure clarifies the framework for information release: the reports describe technical and operational pathways but do not delve into classified details of specific targets. Thus, the existing official narrative records both the overall pattern of utilizing the artificial intelligence model and states that no public document regarding the monitoring of the U.S. fleet or listing of Israeli targets has been released.
Method of abuse: from automation to auxiliary tools
In the case descriptions, the use of the 'Cloud' model for automating surveillance operations and data collection is central. The malicious browser extension used for harvesting identities from social networks exemplifies the connection of auxiliary tools to the data collection flow; connections that can accelerate the cycle of receiving and processing raw information. The company emphasized in its explanations that a significant portion of the abuses relates to older versions of the models, and after the imposition of restrictions, a pattern of migration of some actors to open-source models has been observed.
Alongside the technical description, Anthropic has also listed countermeasures: from blocking identified accounts to strengthening protective systems. The structure of these responses indicates that blocking has been pursued at the account level and updates to protections at the system level; two complementary layers whose common goal is to cut off access to the offending accounts and make it more difficult to replicate the same patterns in the future.
Geographical scope and involved versions
The published reports indicate that the cases under review have originated from various regions. Alongside this geographical dispersion, the footprint of older versions of the models is also prominent; versions that, according to the report, have been more susceptible to abuse than others. The company has simultaneously stated that with the tightening of restrictions, some actors have shifted their path towards open-source models.
These two axes—geographical diversity and version differences—depict an operational field where actors shift between tools depending on access and restrictions. Such shifts highlight the necessity for continuous updates of protective layers for the model-providing platforms.
Distinction between capacity and specific targeting
In parts of the reports, it is explained that information inquiries related to military and security targets can fit within the pattern of utilizing the model. Nevertheless, Anthropic has stated that until the publication of these reports, no public classified details have been released that explicitly show that operators attributed to Iran have monitored the U.S. fleet or produced a list of Israeli targets. This distinction specifies the range of reliable public documentation and emphasizes the current reports' focus on describing processes and tools—not listing specific targets.
In other words, the officially published framework records the general use of the model for data analysis and support for surveillance operations while simultaneously stating that no public document regarding the two specific instances mentioned is available. This summary outlines the current boundaries of knowledge in the public domain.
Countermeasures and accountability pressure on platforms
Anthropic has announced its practical actions with two axes: 'blocking accounts' and 'strengthening protections.' The company's explanations indicate that identifying patterns of abuse has been the pathway for activating these actions, and subsequently, protective updates have been applied. At the same time, a gap remains between what the company has identified and what can be publicly presented and proven; a gap that arises from the classified nature of some parts of the cases.
This situation highlights the accountability pressure on artificial intelligence platforms: on one hand, the expectation for clarification and provision of more details, and on the other hand, the necessity to adhere to protective and classified frameworks. As a result, what is seen in the public output is an accurate description of trends and countermeasures, and the official announcement regarding specific targeting instances is not contingent upon the public release of classified documents.
Case position in the context of previous investigations
Anthropic has introduced this collection as the third series of threat reports since March 2025, stating that around 9 abuse cases have been described in these documents. The arrangement of this collection in line with previous investigations illustrates the position of the case attributed to operators linked to Iran within a broader narrative of how language models have been abused.
On a larger scale, the history of government and affiliated actors' use of artificial intelligence models in recent years has been noted, and the release of this new collection is a continuation of that line of inquiry; a line that documents abuse pathways, auxiliary tools, involved versions, and practical responses from platforms through periodic reports.
Consequences: linking the information field with artificial intelligence tools
The official summary of this case indicates that the cyber and informational struggle between Iran, Israel, and the U.S. has extended to artificial intelligence tools, and platforms are under accountability pressure. Simultaneously, the publicly released evidence remains limited and general, and the announced practical action by the company has been confined to account blocking and strengthening protections.
In this context, the relationship between the technical capabilities of language models and the operational methods of actors remains the focal point of periodic reports: on one hand, the capacity for automating data collection and analysis, and on the other hand, the containment and prevention strategies that companies apply to their infrastructures. The pathway announced by Anthropic on September 10-11, 2026, has outlined these two dimensions in the form of threat reports and executive actions.
Key figures
- Release date: September 10-11, 2026.
- Collection position: third series of threat reports since March 2025.
- Number of cases: around 9 abuse cases have been described.
- Main focus: alleged use by operators linked to Iran of the 'Cloud' model for automating information gathering.
- Actions: blocking identified accounts and strengthening protective systems.
- Mentioned auxiliary tool: malicious browser extension for harvesting identities from social networks.
- Version status: increased abuse with older versions of the model; migration of some actors to open-source models after restrictions were imposed.
- Scope of public disclosure: lack of publication of classified details regarding the monitoring of the U.S. fleet or listing of Israeli targets; emphasis on general use for data analysis and support for surveillance operations.



