Rogue Agent Watch › Records › gtg-2002-vibe-hacking-extortion
GTG-2002 'vibe hacking' AI-driven data-extortion operation
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
In its August 2025 Threat Intelligence Report, Anthropic disclosed a cybercriminal operation it tracked as GTG-2002 that used Claude Code as an active operator to run a scaled data-extortion campaign — a practice Anthropic terms "vibe hacking." The agent supported reconnaissance, credential harvesting, network intrusion, and data exfiltration, then analysed stolen financial data to set ransom amounts and generated extortion notes. Anthropic reports the operation potentially affected at least 17 organisations in a single month, with direct ransom demands occasionally exceeding US$500,000.
Impact as stated
Compromise of personal records including healthcare data, financial information and government credentials; extortion with direct ransom demands occasionally exceeding US$500,000 (reported range US$75,000-500,000 in Bitcoin).
Facts as stated by sources
- Actor
- Unknown cybercriminal (tracked by Anthropic as GTG-2002) (Cybercriminal)
- Category
- AI-orchestrated campaign
- Models named
- Claude Code
- Model families
- Claude (Anthropic)
- Agentic autonomy level
- Supervised-autonomous
- Guardrail bypass
- Legitimate tool abuse
- Attack lifecycle phases
- Reconnaissance, Initial access, Execution, Credential access, Exfiltration, Impact
- Target sectors
- Government, Healthcare, Emergency services, Religious institutions
- Target countries
- not stated
- Organisations affected
- 17
- Records exfiltrated
- not stated
Framework mappings
- MITRE ATLAS
- AML.T0053, AML.T0102, AML.T0016.002
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
- GTG-5004 AI-assisted ransomware-as-a-service operation
- North Korean IT-worker remote-employment fraud using Claude
Sources (2)
- Detecting and countering misuse of AI: August 2025
Anthropic · First-party disclosure · · archived copy - Threat Intelligence Report: August 2025
Anthropic · Vendor report · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "gtg-2002-vibe-hacking-extortion". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/gtg-2002-vibe-hacking-extortion.json — CC BY-SA 4.0.