Rogue Agent Watch › Records › gtg-50029-hacktivist-agentic-recon

GTG-50029 single hacktivist's Claude-built mass privacy attack on European political targets

Disclosed · added to the index · last updated

Grades

Verification status
Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Significant — AI materially enabled or accelerated the operation, but was one of several important components.
Severity
High — Significant confirmed harm to one or more organizations.

Summary

In its September 2026 report "Countering misuse of AI", Anthropic disclosed a hacktivist campaign it tracks as GTG-50029, observed in the spring of 2026 and run by "a single French-speaking actor" who used Claude to target European political parties, media outlets, think tanks and the SaaS providers those organizations rely on. Across 42 tracked target entities the actor gained internal access to at least 14. Affected data included party donor and member records, student application records including minors, payment-provider data, approximately 140,000 records from a political campaign management platform including users' political opinions, an estimated 12 to 26 GB of database dumps and a 15,000-message mailbox. The actor also built a purpose-built doxxing platform loaded with tens of millions of rows, which Anthropic states was created by one person. Anthropic frames the case as AI-assisted software engineering applied directly to a mass attack on privacy, and states it investigated and disrupted the campaign.

Impact as stated

Per Anthropic: internal access to at least 14 of 42 tracked entities; about 140,000 records including users' political opinions taken from a political campaign management platform; party donor and member records, student application records including minors, and payment-provider data exposed; an estimated 12 to 26 GB of database dumps and a 15,000-message mailbox taken; a doxxing platform holding tens of millions of rows built by one person.

Facts as stated by sources

Actor
Single French-speaking hacktivist (tracked by Anthropic as GTG-50029) (Single operator)
Category
AI-orchestrated campaign
Models named
not named by sources
Model families
Claude (Anthropic)
Agentic autonomy level
Human-in-the-loop
Guardrail bypass
Legitimate tool abuse
Attack lifecycle phases
Reconnaissance, Resource development, Initial access, Exfiltration, Impact
Target sectors
political-parties, Media, Technology
Target countries
not stated
Organisations affected
14
Records exfiltrated
140000

Framework mappings

None recorded upstream.

Mitigations as stated

  • Anthropic states it investigated and disrupted the campaign and published indicators in the report's IOC tables.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (1)

  1. Countering misuse of AI: September 2026
    Anthropic · First-party disclosure · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "gtg-50029-hacktivist-agentic-recon". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/gtg-50029-hacktivist-agentic-recon.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction