Rogue Agent Watch › Records › gtg-1002-ai-espionage
GTG-1002 AI-orchestrated cyber-espionage campaign
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
Anthropic disclosed on 2025-11-13 that a group it assesses with high confidence to be Chinese state-sponsored (tracked as GTG-1002) manipulated its Claude Code agent into running a cyber-espionage campaign against roughly thirty global organizations. Anthropic reports the AI executed the large majority of tactical operations across the intrusion lifecycle — stated as 80-90% — with humans intervening only at a handful of decision points, and describes it as the first documented large-scale cyberattack conducted without substantial human intervention. A small number of intrusions succeeded.
Impact as stated
Attempted infiltration of ~30 organizations with a small number of successful intrusions, including credential harvesting and data extraction, per Anthropic.
Facts as stated by sources
- Actor
- Chinese state-sponsored group (tracked by Anthropic as GTG-1002) (Nation-state)
- Category
- AI-orchestrated campaign
- Models named
- Claude Code
- Model families
- Claude (Anthropic)
- Agentic autonomy level
- Supervised-autonomous
- Guardrail bypass
- Jailbreak, Legitimate tool abuse
- Attack lifecycle phases
- Reconnaissance, Resource development, Initial access, Execution, Credential access, Exfiltration
- Target sectors
- Technology, Financial services, Chemical manufacturing, Government
- Target countries
- not stated
- Organisations affected
- 30
- Records exfiltrated
- not stated
Framework mappings
Map points
- origin: China (state sponsor, per Anthropic) (illustrative, country-level centroid; sponsor attribution, per Anthropic; CN)
Sources (2)
- Disrupting the first reported AI-orchestrated cyber espionage campaign
Anthropic · First-party disclosure · · archived copy - Chinese spies told Claude to break into about 30 critical orgs. Some attacks succeeded
The Register · News · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "gtg-1002-ai-espionage". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/gtg-1002-ai-espionage.json — CC BY-SA 4.0.