Rogue Agent Watch › Records › gtg-20006-agentic-espionage

GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus)

Disclosed · added to the index · last updated

Grades

Verification status
Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Significant — AI materially enabled or accelerated the operation, but was one of several important components.
Severity
High — Significant confirmed harm to one or more organizations.

Summary

In its September 2026 report "Countering misuse of AI", Anthropic disclosed a cluster it tracks as GTG-20006 that ran from December 2025 through August 2026. Anthropic describes the attribution as "consistent with public reporting linking the actor to Midnight Blizzard" and one operator's tradecraft and targeting as "consistent with Russian state-nexus espionage". The operator modified Claude Code skills to support intrusions against more than 20 distinct organizations: government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks and defense-industrial companies, concentrated in Ukraine and Europe and extending to the Middle East and Asia. At least three hospitality vendors were compromised and mail records were exfiltrated from at least eight organizations. Humans set targets and reviewed exfiltration, while scheduled jobs renewed stolen access tokens and harvested victim cloud storage with no human involvement. Anthropic states it used AI to extract and organize hundreds of gigabytes of stolen data, including more than 300,000 national identity records and registry data on more than half a million companies taken from a North African government technology authority.

Impact as stated

Per Anthropic: at least three hospitality vendors compromised; mail records exfiltrated from at least eight organizations; hundreds of gigabytes of stolen data extracted and organized with AI, including more than 300,000 national identity records and commercial registry data on more than half a million companies from a North African government technology authority.

Facts as stated by sources

Actor
Russia-nexus espionage actor (tracked by Anthropic as GTG-20006; attribution described as consistent with public reporting on Midnight Blizzard) (Nation-state)
Category
AI-orchestrated campaign
Models named
Claude Code
Model families
Claude (Anthropic)
Agentic autonomy level
Supervised-autonomous
Guardrail bypass
Legitimate tool abuse
Attack lifecycle phases
Initial access, Credential access, Persistence, Exfiltration
Target sectors
Government, Defense, hospitality
Target countries
UA
Organisations affected
20
Records exfiltrated
300000

Framework mappings

None recorded upstream.

Mitigations as stated

  • Anthropic states it disrupted the activity, strengthened its safeguards and shared intelligence with authorities and industry partners where appropriate.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (1)

  1. Countering misuse of AI: September 2026
    Anthropic · First-party disclosure · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "gtg-20006-agentic-espionage". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/gtg-20006-agentic-espionage.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction