AI incident ·
Anthropic-Designated GTG-87001 Weapons Cell in Northern Yemen Reportedly Used Claude Code to Develop Missile Guidance Software
In brief
An AI system built by Large language model developers, Chatbot developers and 2 others and deployed by Threat actors, GTG-87001 and 1 other allegedly harmed National security and intelligence stakeholders.
- Risk domain
- Not classified
- Occurred
- Coverage
- 1 report
What happened
Anthropic reported that a northern Yemen-based weapons cell, designated GTG-87001, used Claude Code across three weapons programs to develop guidance, navigation, and control software. The actors reportedly test-fired a guided rocket that appeared to fail, then returned to Claude for failure analysis. Anthropic said it banned associated accounts and shared threat intelligence with partners.
Editor's notes
(1) Incident ID date 09/10/2026 uses Anthropic's first public disclosure because no GTG-87001-specific event date was disclosed; the report covers activity from 12/2025–08/2026. (2) Anthropic said it banned associated accounts, shared threat intelligence with public- and private-sector partners, and strengthened safeguards. (3) On 09/11/2026, FT and AP connected the northern Yemen location to Houthi-controlled territory, but Anthropic did not identify the actors as Houthis.
Laws that address this harm
No recorded instrument yet addresses this use case where it happened. See the open queue.
Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).
News reports (1)
Titles link to the original publisher; report text is not reproduced here.
Who was involved
- Alleged deployer
- Threat actors GTG-87001 Chatbot users
- Alleged developer
- Large language model developers Chatbot developers Anthropic AI agent system developers
- Alleged harmed party
- National security and intelligence stakeholders
AI systems implicated
Large language modelsClaude CodeClaudeChatbotsAI agent systems
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —
Related incidents
Linked by editors or by text similarity in the source dataset.
Other incidents involving Threat actors
- AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns
- Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
- Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook
- Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package
Source record: incident #1687 on the AI Incident Database · all 1 report