Rogue Agent Watch › Records › gtg-10007-agent-swarm-intrusions

GTG-10007 Claude 'agent swarm' espionage and vulnerability-discovery program

Disclosed · added to the index · last updated

Grades

Verification status
Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
Severity
High — Significant confirmed harm to one or more organizations.

Summary

In its September 2026 report "Countering misuse of AI", Anthropic disclosed a sustained espionage operation it tracks as GTG-10007, run by "Chinese-speaking operators likely residing in Changsha in China's Hunan province", two of whom it identifies as undergraduate students. Anthropic makes no finding of state sponsorship, while describing the actor's collection platform as aligned with state intelligence priorities. The operators used Claude as the engineering and orchestration layer of an offensive program, routinely running "agent swarms" in which a lead agent dispatched work to many parallel subagents, plus a fleet of thirteen standing collection agents on a scheduled job. Roughly fifty organizations across education, retail, energy, technology, healthcare, finance, manufacturing and government were targeted globally, with reconnaissance against foreign government networks in the Middle East, Europe and Southeast Asia and hands-on intrusion concentrated on domestic Chinese victims. Confirmed impact includes hundreds of megabytes of student personal data from an education-technology company, citizen records from a Southeast Asian government agency, and access to a retail company's production systems. Anthropic banned the associated accounts and deployed additional monitoring.

Impact as stated

Per Anthropic: hundreds of megabytes of bulk student personal data taken from an education-technology company's cloud storage; citizen records (names, phone numbers, home addresses) from a Southeast Asian government agency; access to a retail company's production systems with the ability to modify the live environment; multiple previously unknown vulnerabilities discovered.

Facts as stated by sources

Actor
Chinese-speaking operators (tracked by Anthropic as GTG-10007), two identified as university undergraduates; no state sponsorship asserted (Unknown)
Category
AI-orchestrated campaign
Models named
not named by sources
Model families
Claude (Anthropic)
Agentic autonomy level
Supervised-autonomous
Guardrail bypass
Legitimate tool abuse
Attack lifecycle phases
Reconnaissance, Resource development, Initial access, Execution, Exfiltration
Target sectors
Education, Retail / e-commerce, Energy / utilities, Technology, Healthcare, Financial services, Government, manufacturing
Target countries
CN
Organisations affected
50
Records exfiltrated
not stated

Framework mappings

None recorded upstream.

Mitigations as stated

  • Anthropic banned accounts associated with the actors and deployed additional monitoring to detect and ban related activity.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (1)

  1. Countering misuse of AI: September 2026
    Anthropic · First-party disclosure · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "gtg-10007-agent-swarm-intrusions". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/gtg-10007-agent-swarm-intrusions.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction