Rogue Agent Watch › Records › gtg-1002-ai-espionage

GTG-1002 AI-orchestrated cyber-espionage campaign

Disclosed · added to the index · last updated

Grades

Verification status
Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
Severity
High — Significant confirmed harm to one or more organizations.

Summary

Anthropic disclosed on 2025-11-13 that a group it assesses with high confidence to be Chinese state-sponsored (tracked as GTG-1002) manipulated its Claude Code agent into running a cyber-espionage campaign against roughly thirty global organizations. Anthropic reports the AI executed the large majority of tactical operations across the intrusion lifecycle — stated as 80-90% — with humans intervening only at a handful of decision points, and describes it as the first documented large-scale cyberattack conducted without substantial human intervention. A small number of intrusions succeeded.

Impact as stated

Attempted infiltration of ~30 organizations with a small number of successful intrusions, including credential harvesting and data extraction, per Anthropic.

Facts as stated by sources

Actor
Chinese state-sponsored group (tracked by Anthropic as GTG-1002) (Nation-state)
Category
AI-orchestrated campaign
Models named
Claude Code
Model families
Claude (Anthropic)
Agentic autonomy level
Supervised-autonomous
Guardrail bypass
Jailbreak, Legitimate tool abuse
Attack lifecycle phases
Reconnaissance, Resource development, Initial access, Execution, Credential access, Exfiltration
Target sectors
Technology, Financial services, Chemical manufacturing, Government
Target countries
not stated
Organisations affected
30
Records exfiltrated
not stated

Framework mappings

MITRE ATLAS
AML.T0054, AML.T0102, AML.T0053

Map points

  • origin: China (state sponsor, per Anthropic) (illustrative, country-level centroid; sponsor attribution, per Anthropic; CN)

Sources (2)

  1. Disrupting the first reported AI-orchestrated cyber espionage campaign
    Anthropic · First-party disclosure · · archived copy
  2. Chinese spies told Claude to break into about 30 critical orgs. Some attacks succeeded
    The Register · News · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "gtg-1002-ai-espionage". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/gtg-1002-ai-espionage.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction