Anthropic Says Yemen Cell Used Claude to Build Missile Software
Security / news
Anthropic Says Yemen Cell Used Claude to Build Missile Software
The company's September threat report says the group ran three weapons programs and test-fired a guided rocket that failed, then returned to Claude within hours to ask why.
A weapons-engineering cell operating in northern Yemen, territory largely controlled by the Houthi movement, used Claude "in place of human software engineers" to write guidance, navigation and control software for missiles and a guided rocket, Anthropic said in a threat intelligence report published Friday.
The activity ran from December 2025 to August 2026 and involved Claude's Haiku, Sonnet and Opus models, according to the report. Anthropic said it detected the operation through an internal investigation, banned the accounts involved, and shared details of the case with government and industry partners it did not name.
Three weapons programs, one flight computer built from phone parts
Anthropic said the cell was running three programs at once: a guided rocket built around a commodity, phone-class flight computer with a homing system for its final approach; a multi-stage ballistic missile with a range goal above 2,000 kilometers; and a separate missile family, referred to internally as the R2000 set, that included a hypersonic glide vehicle variant.
| Program | What the report says about it |
|---|---|
| Guided rocket | Commodity phone-class flight computer, homing guidance for final approach |
| Ballistic missile | Multi-stage design, range goal above 2,000 km |
| R2000 missile family | Includes a hypersonic glide vehicle variant |
The group ran several Claude instances in parallel with separate assignments, one writing code, one doing research and a third reviewing the first instance's output, while human operators directed the work rather than doing it themselves, according to the report. The cell got past Anthropic's safeguards, according to reporting on the report, by concealing its intentions and splitting the work across separate sessions, so no single conversation exposed the full scope of a weapons program to the classifiers screening for misuse.
The Yemen case is one of seven harm categories in Anthropic's September report, alongside cyber operations, influence operations, surveillance, scams and fraud, biological misuse and illicit distillation, all covering activity the company says it disrupted between December 2025 and August 2026.
A failed launch, then a return to Claude within hours
Anthropic said it has no evidence the cell fielded an operational weapon built with Claude's help. The group did test-fire a guided rocket, according to the report, and the launch appears to have failed; within hours, the actors returned to Claude to try to work out what had gone wrong. The cell had also built an offline simulation toolkit that runs without Claude or commercial tools such as MATLAB, meaning a future ban on its accounts would not by itself stop the work.
This is the third weapons-adjacent misuse case Anthropic has disclosed in 2026, after a student-run exploit foundry it linked to Chinese actors and a separate case tying a hotel WiFi hijacking operation to the Russian group Midnight Blizzard. Anthropic has not said whether the three cases share any infrastructure or tooling.
Anthropic did not name the government or industry partners it briefed on the Yemen case, and it did not say whether banning the accounts meaningfully slowed a program that already had an offline toolkit in place. The company's next disclosure of disrupted misuse activity, under its current cadence, would fall in its October report.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.