Rogue Agent Watch › Records › gtg-10007-agent-swarm-intrusions
GTG-10007 Claude 'agent swarm' espionage and vulnerability-discovery program
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
In its September 2026 report "Countering misuse of AI", Anthropic disclosed a sustained espionage operation it tracks as GTG-10007, run by "Chinese-speaking operators likely residing in Changsha in China's Hunan province", two of whom it identifies as undergraduate students. Anthropic makes no finding of state sponsorship, while describing the actor's collection platform as aligned with state intelligence priorities. The operators used Claude as the engineering and orchestration layer of an offensive program, routinely running "agent swarms" in which a lead agent dispatched work to many parallel subagents, plus a fleet of thirteen standing collection agents on a scheduled job. Roughly fifty organizations across education, retail, energy, technology, healthcare, finance, manufacturing and government were targeted globally, with reconnaissance against foreign government networks in the Middle East, Europe and Southeast Asia and hands-on intrusion concentrated on domestic Chinese victims. Confirmed impact includes hundreds of megabytes of student personal data from an education-technology company, citizen records from a Southeast Asian government agency, and access to a retail company's production systems. Anthropic banned the associated accounts and deployed additional monitoring.
Impact as stated
Per Anthropic: hundreds of megabytes of bulk student personal data taken from an education-technology company's cloud storage; citizen records (names, phone numbers, home addresses) from a Southeast Asian government agency; access to a retail company's production systems with the ability to modify the live environment; multiple previously unknown vulnerabilities discovered.
Facts as stated by sources
- Actor
- Chinese-speaking operators (tracked by Anthropic as GTG-10007), two identified as university undergraduates; no state sponsorship asserted (Unknown)
- Category
- AI-orchestrated campaign
- Models named
- not named by sources
- Model families
- Claude (Anthropic)
- Agentic autonomy level
- Supervised-autonomous
- Guardrail bypass
- Legitimate tool abuse
- Attack lifecycle phases
- Reconnaissance, Resource development, Initial access, Execution, Exfiltration
- Target sectors
- Education, Retail / e-commerce, Energy / utilities, Technology, Healthcare, Financial services, Government, manufacturing
- Target countries
- CN
- Organisations affected
- 50
- Records exfiltrated
- not stated
Framework mappings
None recorded upstream.
Mitigations as stated
- Anthropic banned accounts associated with the actors and deployed additional monitoring to detect and ban related activity.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
- GTG-1002 AI-orchestrated cyber-espionage campaign
- GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus)
- GTG-50014 ShinyHunters-linked agentic mass data theft and extortion
- GTG-50029 single hacktivist's Claude-built mass privacy attack on European political targets
- GTG-50020 autonomous exploitation pipeline against ~30 AI companies and theft of production API keys
Sources (1)
- Countering misuse of AI: September 2026
Anthropic · First-party disclosure · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "gtg-10007-agent-swarm-intrusions". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/gtg-10007-agent-swarm-intrusions.json — CC BY-SA 4.0.