Rogue Agent Watch › Records › gtg-50014-agentic-mass-exfiltration
GTG-50014 ShinyHunters-linked agentic mass data theft and extortion
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- Critical — Broad real-world harm — e.g. many organizations compromised, large-scale exfiltration, or critical-infrastructure impact.
Summary
In its September 2026 report "Countering misuse of AI", Anthropic disclosed a financially motivated cluster it tracks as GTG-50014, whose operators it describes as "suspected to be affiliates of the ShinyHunters collective". Between December 2025 and August 2026 the affiliates used Claude across multiple intrusions: a technology provider lost more than a terabyte of data including hundreds of thousands of national identifiers and millions of payment card records; an airline lost tens of millions of passenger records; an energy company, a French retail chain, a Web3 identity platform, a nonprofit and an enterprise software company were also hit; and a SaaS provider compromise reached roughly 200 downstream customer organizations. Over 2,100 Azure AD token sets spanning more than 40 corporate tenants were harvested in about 34 hours. Anthropic states that for the SaaS session-store dump "AI agents performed nearly all of the work", with humans setting targets and reviewing exfiltration. Anthropic detected and banned the associated accounts and engaged authorities, industry partners and victims.
Impact as stated
Per Anthropic: more than a terabyte of data exfiltrated from a technology provider, including hundreds of thousands of national identifiers and millions of payment card records; tens of millions of passenger records from an airline; over 2,100 Azure AD token sets across more than 40 corporate tenants; a SaaS provider compromise exposing roughly 200 downstream customer organizations; a ~400,000-record telecom/ISP dataset aggregated into a searchable service. Pay-or-leak extortion is the stated business model.
Facts as stated by sources
- Actor
- Suspected ShinyHunters affiliates (tracked by Anthropic as GTG-50014) (Cybercriminal)
- Category
- AI-orchestrated campaign
- Models named
- not named by sources
- Model families
- Claude (Anthropic)
- Agentic autonomy level
- Supervised-autonomous
- Guardrail bypass
- Unknown
- Attack lifecycle phases
- Initial access, Credential access, Exfiltration, Impact
- Target sectors
- Technology, Energy / utilities, Retail / e-commerce, Telecommunications, aviation, nonprofit
- Target countries
- FR
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
None recorded upstream.
Mitigations as stated
- Anthropic detected and banned accounts associated with the ShinyHunters associates, implemented measures to detect and disrupt future misuse from the actors, and engaged government authorities, industry partners and victims to remediate.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
- GTG-2002 'vibe hacking' AI-driven data-extortion operation
- GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus)
- GTG-10007 Claude 'agent swarm' espionage and vulnerability-discovery program
- GTG-50029 single hacktivist's Claude-built mass privacy attack on European political targets
- GTG-50020 autonomous exploitation pipeline against ~30 AI companies and theft of production API keys
Sources (1)
- Countering misuse of AI: September 2026
Anthropic · First-party disclosure · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "gtg-50014-agentic-mass-exfiltration". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/gtg-50014-agentic-mass-exfiltration.json — CC BY-SA 4.0.