Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Anthropic Bans Israeli-Linked and Iran-Linked Accounts for Using Claude to Profile Rival Nations' Citizens

Anthropic's threat intelligence team spent nine months, from December 2025 through August 2026, watching state-linked hackers, spyware vendors and propaganda shops try to turn its Claude models into intelligence assets. On September 10, the company published what it found, according to Crypto Briefing.
The report groups the misuse into seven categories: cyber operations, foreign influence campaigns, surveillance architecture, fraud, biological misuse, conventional arms development, and model distillation, according to Anadolu Agency. Anthropic told Anadolu it disrupted the accounts, tightened its safety filters, and shared findings with government authorities and industry peers "where appropriate."
The Israel-Linked Surveillance Operation
One banned account was tied to S2T Unlocking Cyberspace, described in the report as an Israeli-Singaporean commercial intelligence vendor, according to The Cradle and Crypto Briefing. The operator fed Claude batches of roughly 25 social media posts at a time and had it classify each poster's location, demographic group, and political leaning, complete with confidence scores, per The Cradle.
The system sorted people into six categories: urban, clerical, military, youth, diaspora and rural. Output was written in formal Arabic styled as government communications, with sentiment breakdowns by Gulf nationality and recommended counter-messaging attached, according to the same reporting.
Anthropic also found the operator had assembled more than 255 fake social media accounts across Persian, Arabic, English and German, designed to pass as both pro- and anti-government Iranian voices, according to Crypto Briefing. Anthropic said this looked like an inventory of sockpuppets built for later use, not yet deployed.
Anthropic said it caught the operation at the pilot stage. The company found no evidence the fake accounts or profiling data were used against real people before the account was banned in June 2026, according to Crypto Briefing. Anthropic also said the capabilities matched a 2023 investigation by Forbidden Stories into an S2T surveillance brochure recovered from leaked Colombian military files.
Anthropic's report does not establish that Israel's government, or Mossad specifically, directed this operation. It identifies a commercial vendor. Kayhan, Iran's state-linked newspaper, ran the story under the headline "Israel's AI War on Iran" and tied it directly to Mossad, layering in a separate, previously reported story: Channel 12's August account that Mossad chief Roman Gofman dismissed two senior officials over a failed plan to trigger Iranian regime change, reportedly coordinated with Washington. That dismissal story is real reporting, but it comes from Channel 12 and the New York Times, not from Anthropic's findings, and Kayhan blends the two into a single narrative the underlying report does not support.
The Iran-Linked Mirror Image
Anthropic's report cuts both ways. An Iran-linked account built what the company called an automated, open-source intelligence profiling harness targeting Israeli government officials, private citizens, and organizations tied to Jewish communities outside Israel, according to News Beep. The same account was separately modifying an open-source credential-theft tool called NanoDump and building software to hide the resulting malware from security researchers, per the same report.
A related Iran-linked operation compiled targeting material on U.S. naval forces, cross-referencing satellite imagery, ship-tracking data and photos of military personnel scraped from public sources, News Beep reported. The same actor built a domestic surveillance system for Iranian state use, combining license-plate recognition with phone-identifier interception, and reportedly developed a case-management tool called "Arman" along with a malicious browser extension aimed at dissidents, according to Crypto Briefing.
Russia and China Get Top Billing in the Actual Report
Buried under the Israel-Iran angle that dominated some coverage, the bulk of Anthropic's report is about Russia and China. A Russian actor consistent with the espionage group Midnight Blizzard used Claude to reverse-engineer military drone software kits, extract mailboxes from drone component manufacturers, and build malware that autonomously rewrote itself when antivirus tools flagged it, according to Anadolu. The same actor allegedly breached a North African government tech authority, exposing more than 300,000 national ID records and files on more than half a million businesses.
Anadolu's own headline flags something worth considering. Its framing points out the report details foreign state misuse while "omitting US defense contracts," a pointed observation given Anthropic itself holds contracts with the U.S. government. No source here alleges wrongdoing tied to that omission, but it is a fair question for a company positioning itself as a neutral referee of state-actor misuse while also selling to one of the states involved.
What's Actually Unresolved
Anthropic says none of the surveillance or targeting operations reached real victims before it intervened. That claim rests entirely on Anthropic's own detection, since these are commercial accounts on a system Anthropic controls, not independently audited outcomes. Whether S2T's platform, Iran's Arman system, or the naval-targeting tool were ever deployed through other AI providers, or built independently once cut off from Claude, is a question Anthropic's report does not answer.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.