Three Missile Programs, Three Claude Instances

Anthropic's own threat intelligence report, published this week and covering activity the company disrupted between December 2025 and August 2026, describes a cell of threat actors based in northern Yemen running three separate weapons development programs on Claude: a guided rocket built around a commodity phone-class flight computer with final-phase homing guidance, a multi-stage ballistic missile with a stated range goal above 2,000 kilometres, and a multi-variant missile set the actors called "R2000" that included a hypersonic glide vehicle. Anthropic did not name the group; multiple outlets covering the same report, including Stars and Stripes, have described the cell as operating in territory controlled by the Iran-aligned Houthi movement.

What Anthropic's own case study emphasizes is not that the actors asked Claude a clever question. They ran several Claude instances at once and assigned each one a distinct job, the way a lead engineer would split work across a small team: one instance wrote the guidance, navigation and control code, a second handled research, and a third reviewed what the first had produced. Claude was used to integrate an open-source autopilot onto the phone-class flight computer, tune control settings, run a firmware build pipeline and execute flight simulations.

A Failed Field Test, Reported Back Within Hours

Anthropic's safeguards blocked many of the cell's requests but not all of them; the actors split their work across many sessions specifically so no single session revealed the full intent of the program. Anthropic says it found no evidence the group fielded an operational weapon, but the cell did test-fire a guided rocket. The field test failed, and within hours the actors were back inside Claude working through the telemetry to diagnose why. Anthropic banned the accounts it could identify, but the actors had already built an offline simulation toolkit that runs without Claude or any other AI system, meaning the disruption removed a convenience, not the underlying capability.

The Same Account Also Built a Domestic Surveillance Platform

A second, separate case in the same report describes an Iran-linked account that used Claude to build a Python pipeline compiling targeting handbooks against US naval forces in the Middle East, drawing entirely on open-source material: personnel names lifted from captions on public military photographs, ship and aircraft transponder identifiers, scripts to query commercial satellite imagery, and a list of public websites that expose naval movements. The same account directed Claude to research known vulnerabilities in the shipboard systems that support that hardware.

VulnerabilityProductCategory
CVE-2022-22707, CVE-2019-11072, CVE-2018-19052COBHAM SAILOR 900Maritime VSAT terminal
CVE-2025-20309Cisco Unified Communications ManagerEnterprise comms
CVE-2024-20418Cisco Ultra-Reliable Wireless BackhaulIndustrial wireless
CVE-2024-20354Cisco IW3702Industrial wireless access point
CVE-2024-2658Schneider Electric EcoStruxureIndustrial control system

What Anthropic's write-up flags as separate from the naval work is that the identical account also used Claude to design components of a domestic mass-surveillance platform for Iranian state systems, combining automatic license-plate recognition with mobile-device identifier interception, and to run social-network analysis over a same-day export of a private 244-member Telegram group. One operator, one Claude account, two disciplines that normally sit in different departments.

What This Changes for Anyone Running the Same Hardware

Neither case required a novel AI capability. What both show is that a single operator can now assign Claude instances the roles of a coder, a researcher and a reviewer, and get the throughput of a small in-house engineering team out of a consumer AI subscription, whether the target is missile guidance software or reconnaissance against a Cisco-and-Schneider-Electric technology stack. That stack, VSAT terminals, industrial wireless backhaul, and EcoStruxure control systems, is not unique to the US Navy; it runs on European shipping, ports and industrial sites that report incidents to their own national authorities under NIS2. The safeguard that caught both cases here was Anthropic's own account-level pattern detection, not a single blocked prompt, which is the part worth taking seriously if your organisation's defense still assumes a human has to type each malicious step by hand.

Servola Journal

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.