Rogue Agent Watch › Records › gtg-20006-agentic-espionage
GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus)
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Significant — AI materially enabled or accelerated the operation, but was one of several important components.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
In its September 2026 report "Countering misuse of AI", Anthropic disclosed a cluster it tracks as GTG-20006 that ran from December 2025 through August 2026. Anthropic describes the attribution as "consistent with public reporting linking the actor to Midnight Blizzard" and one operator's tradecraft and targeting as "consistent with Russian state-nexus espionage". The operator modified Claude Code skills to support intrusions against more than 20 distinct organizations: government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks and defense-industrial companies, concentrated in Ukraine and Europe and extending to the Middle East and Asia. At least three hospitality vendors were compromised and mail records were exfiltrated from at least eight organizations. Humans set targets and reviewed exfiltration, while scheduled jobs renewed stolen access tokens and harvested victim cloud storage with no human involvement. Anthropic states it used AI to extract and organize hundreds of gigabytes of stolen data, including more than 300,000 national identity records and registry data on more than half a million companies taken from a North African government technology authority.
Impact as stated
Per Anthropic: at least three hospitality vendors compromised; mail records exfiltrated from at least eight organizations; hundreds of gigabytes of stolen data extracted and organized with AI, including more than 300,000 national identity records and commercial registry data on more than half a million companies from a North African government technology authority.
Facts as stated by sources
- Actor
- Russia-nexus espionage actor (tracked by Anthropic as GTG-20006; attribution described as consistent with public reporting on Midnight Blizzard) (Nation-state)
- Category
- AI-orchestrated campaign
- Models named
- Claude Code
- Model families
- Claude (Anthropic)
- Agentic autonomy level
- Supervised-autonomous
- Guardrail bypass
- Legitimate tool abuse
- Attack lifecycle phases
- Initial access, Credential access, Persistence, Exfiltration
- Target sectors
- Government, Defense, hospitality
- Target countries
- UA
- Organisations affected
- 20
- Records exfiltrated
- 300000
Framework mappings
None recorded upstream.
Mitigations as stated
- Anthropic states it disrupted the activity, strengthened its safeguards and shared intelligence with authorities and industry partners where appropriate.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
- GTG-1002 AI-orchestrated cyber-espionage campaign
- GTG-2002 'vibe hacking' AI-driven data-extortion operation
- GTG-50014 ShinyHunters-linked agentic mass data theft and extortion
- GTG-10007 Claude 'agent swarm' espionage and vulnerability-discovery program
- GTG-50029 single hacktivist's Claude-built mass privacy attack on European political targets
- GTG-50020 autonomous exploitation pipeline against ~30 AI companies and theft of production API keys
Sources (1)
- Countering misuse of AI: September 2026
Anthropic · First-party disclosure · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "gtg-20006-agentic-espionage". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/gtg-20006-agentic-espionage.json — CC BY-SA 4.0.