Cyber operations · Field report

From assistant to orchestrator: Anthropic’s September 2026 threat intelligence report

Humans retain objectives and decisions. AI handles execution, orchestration and data processing.

Stolen keys return as compute for further attacksGTG-50014 / GTG-50020 Human decisions Targets · review · monetization Attacker’s AI workflow Reconnaissance and executionRepeated work across targets Customer environment Targeted systems Applications · cloud · vendors Operations Steal access credentials API key / session token From customers, not Anthropic itself Switch to victim-funded AI Observed key-reuse pattern, not a single composite intrusion.Stolen keys return as compute for further attacksGTG-50014 / GTG-50020 Human decisions Targets · review · monetization Attacker’s AI workflow Reconnaissance, execution and results Operations Customer environment Targeted systems API key / session token Stolen keys fund further AI use Customer compromise ≠ Anthropic compromise
Context

Work delegated to AI

Anthropic’s September 2026 threat intelligence report describes real cases in which external actors incorporated AI into cyber operations. It is a service provider’s account of activity detected and disrupted on its own platform, not an independent investigation of every incident, a benchmark of model capability, or an estimate of how common these practices are across the wider threat landscape. The selected cases were notable or novel examples of misuse. Its threat-intelligence index dates the report to September 10, 2026, while the incidents span December 2025 through August 2026.

The report covers seven harm areas. This account is limited to cyber operations: GTG-20006, GTG-50014, GTG-10007, GTG-50021, GTG-50020, GTG-50029, the cyber overview and Appendix A. Influence operations, surveillance, scams and fraud outside the GTG-50020 workflows, biological misuse, conventional weapons development and model distillation remain out of scope.

The internal Generative Threat Group (GTG) designators distinguish actors observed abusing AI; they do not establish an organization's public identity. The cyber cases involved Anthropic's Claude models Haiku, Sonnet and Opus. No malicious cyber activity involving the Claude Fable or Claude Mythos models was identified in this section. This observation does not establish intrinsic model safety, and the separate distillation exception falls outside the cyber cases.

Across the cases, the recurring pattern was work delegated to AI. A human supplied an objective. An AI agent interpreted the target environment, divided work into tasks, called software tools, processed their output and repeated the process. Orchestration joined several such agents into one workflow, sometimes with parallel subagents and persistent state that carried target lists, credentials and previous findings between sessions. Human operators still selected targets, reviewed results and decided how to use or monetize what they obtained.

Speed · scale · depth

Speed, scale and depth

Anthropic evaluates what it calls AI “uplift” through three lenses: speed, scale and depth. These are the company’s analytical categories, not the results of a controlled causal measurement. Speed concerns how quickly an operation proceeds. Scale covers the number of targets or tasks an actor can handle. Depth concerns the range and complexity of work the actor can perform.

The cases extend AI use beyond conversational assistance. Some actors asked for code or technical explanations. Others let agents execute tools against environments, maintain campaign state and dispatch work in parallel. Several operations continued for hours or days, and scheduled collection or token-renewal tasks sometimes ran without a person present.

A comparable operating pattern appeared in the company's 2025 account of a suspected state-sponsored campaign. The 2026 cases show variants of it among espionage operators, financially motivated groups and individuals. Public offensive-agent frameworks such as PentAGI provide ready-made scaffolding for dividing work, invoking tools and retaining results, reducing the amount of orchestration software an operator must build independently.

This diffusion does not make the cases one connected campaign, nor does it mean every operation was autonomous. AI appears at different points on a spectrum, from engineering assistance through human-directed execution to long-running parallel workflows. Familiar access methods also remain prominent: actors use stolen credentials, phishing, exposed services and unpatched systems while also researching newly discovered flaws.

01
Roles and state

Which decisions stay human, and which work moves to AI

Which decisions stay human, and which work moves to AI Operator AI workflow Select targets andobjectives Decompose work; invoke tools or dispatch subagents Set objective Reconnaissance Execution Data processing Review results; decidehow to monetize Results return to humans; not per-tool approval GTG-10007: persistent campaign memory Target lists · credentials · engagement state · standing instructions Autonomy varies by case and step.These are representative roles.
↔ Scroll horizontally to view the full diagram
Based on the overview and GTG-10007. Human participation does not imply approval before every tool call. [Official] Anthropic
GTG-20006

GTG-20006: espionage, retooling and collection

Anthropic describes GTG-20006 as a Russian state-nexus espionage actor. Its attribution is reported as consistent with public reporting linking the activity to Midnight Blizzard, Microsoft's tracking name for a Russia-based threat actor engaged in long-term espionage. One observed Russian-speaking operator used the handle JackPoterz. The group’s targets included Ukrainian and European government, military, diplomatic and defense organizations, US foreign-policy interests and military-drone supply chains.

More than 20 organizations were identified across operational planning, reconnaissance and live activity. That number represents targets observed at different stages, not more than 20 confirmed compromises. The target set also included government-related maritime organizations in Asia and a North African government technology authority.

GTG-20006 maintained a cross-platform toolkit covering Windows implants, mobile exploitation, browser-credential theft, phishing infrastructure and an administrative console for compromised accounts. AI agents monitored whether deployed artifacts were being detected. When a security product flagged one, the workflow analyzed the detection, modified the artifact, rebuilt it and prepared the replacement for redeployment. The human operator mainly intervened to refine reusable task instructions, or skills, in the AI coding tool Claude Code.

This created a detect, rewrite, rebuild and redeploy loop. Anthropic judges that, at least in theory, such a loop can let capable adversaries adapt faster than defenders can develop and deploy new static detections. The claim concerns the cost imposed by static detections alone; it does not establish that all traditional defenses have failed.

02
GTG-20006

What happens after a security product detects the toolkit

What happens after a security product detects the toolkit GTG-20006 · toolkit-maintenance subworkflow Monitor deployedtools Detection by securityproducts? Modify detectedartifacts Identify and rework theartifacts Rebuild Check detection again Detected Still detected: iterate Redeploy Return to liveoperations Undetected Return to monitoring the deployed toolkit Human refines Claude Codeskills This subworkflow does not make the whole operation human-free
↔ Scroll horizontally to view the full diagram
Detection triggers rework; persistent detection loops back, while an undetected artifact is redeployed. The source qualifies the speed advantage as “at least in theory.” [Official] Anthropic

The actor also used AI in phishing and infrastructure management. Workflows researched and registered domains, configured hosting, sent messages and monitored command-and-control channels. Through these command-and-control (C2) channels, the attacker managed compromised systems and received results. Device-code phishing abused a legitimate cloud sign-in process by inducing a victim to authorize an attacker-controlled session. AI prepared supporting infrastructure and tools, while some commands against victim systems were executed under human direction.

The operations extended through several distinct access and collection paths. At least three hospitality vendors operating hotel WiFi were compromised. The actor changed DNS records, which determine where an internet name directs traffic, so that guests were diverted to actor-controlled infrastructure. This DNS hijacking exposed guest traffic, device identifiers and IP addresses. Information from hotel management systems could then be combined with information obtained from individual devices to focus subsequent targeting, including people associated with Ukraine and drone manufacturing.

Drone technology was another recurring target. The actor bulk-exported mailboxes from at least two drone-component manufacturers, targeted a military drone maker and stole a proprietary software development kit for a drone-vision system. It analyzed the kit to recover product architecture, hardware components, supplier dependencies and information about an unannounced product.

A WhatsApp collection platform linked victim accounts to actor-controlled companion devices and suppressed read receipts while exporting Russian- and Ukrainian-language conversations. At least two former senior Ukrainian officials were targeted. Both individuals are described as targets, without confirmation that both attempts resulted in compromise. In another operation, authorization flaws in camera-streaming services enabled access to live camera feeds.

The intrusion into a North African government technology authority began with stolen VPN credentials. The actor used them to take control of a central account server and exfiltrated its credential database, including more than 300,000 national identity records and commercial registry information for more than half a million companies. These were North African records, not Ukrainian data.

A cloud-mail espionage platform used device-code phishing against diplomatic and government personnel. It resulted in access to and exfiltration of mail records from at least eight organizations. Fake-update lures delivered credential-stealing and remote-access payloads, some designed to freeze security updates on victim machines so that later detection signatures would not be retrieved or run.

AI had four roles in this activity. First, it supported reconnaissance by fingerprinting email and remote-access systems and organizing public information into target lists. Second, it helped build and operate the initial-access platform, while some intrusion steps remained directed by the actor. Third, it extracted and organized hundreds of gigabytes of stolen material, including bulk mailbox exports. Fourth, it helped preserve access by registering actor-controlled devices with compromised organizational accounts.

The result was not an operation without humans. It was an espionage workflow in which tooling, infrastructure, collection and persistence could continue through reusable AI-driven processes while the operator refined objectives and reviewed results.

GTG-50014

GTG-50014: credentials, cross-tenant theft and monetization

GTG-50014 covers multiple financially motivated operators suspected of affiliation with the ShinyHunters collective. Their activity was grouped by related objectives and methods, but the affiliates retained separate tooling, workflows and intrusions. Their operations should not be compressed into a single actor or incident.

One French-speaking operator using the aliases frkoo, MeowSHA and blazespider ran a distributed credential-harvesting pipeline across 10 AWS EC2 workers. EC2 instances were the actor’s rented cloud computers. The pipeline downloaded 1.8 million distinct Android APKs, the package files used to distribute Android applications. It decompiled those packages and scanned them with TruffleHog, a tool for finding embedded passwords, tokens and other secrets. Verified findings were sent to Telegram and organized into over 100 source types. A parallel stream harvested GitHub access tokens.

The source describes an actor-built pipeline combining deterministic tools with AI-assisted interpretation and subsequent operations. It does not assign every download, decompilation or scanner invocation to an autonomous language model.

The actor also operated a storefront for stolen payment-card and personal data. A domain impersonating the French national police served, in Anthropic’s judgment, as branding for the criminal shop rather than as a phishing lure. Operational-security lapses exposed parts of the actor's infrastructure and credentials, whose values are not reproduced here.

The resulting compromises varied in impact. More than a terabyte of data was stolen from one technology provider and staged publicly to pressure the victim. At an airline, the actors accessed systems holding tens of millions of passenger records; the extent of theft from those records was not specified. At an energy company, remote control of residential electric-vehicle charging current was an actor claim, not an independently confirmed outcome.

A separate suspected affiliate appeared to specialize in reaching customers through a software provider. Within the software-as-a-service (SaaS) platform, each customer organization had its own tenant. After compromising one SaaS provider, the operator extracted data belonging to roughly 200 downstream customer organizations. It then dumped a session store containing over 2,100 token sets for Microsoft's cloud identity service Azure AD across more than 40 corporate tenants in about 34 hours. These authenticated-session credentials let a system recognize an already signed-in user or application without repeating the original login. AI performed nearly all this work.

03
GTG-50014

Industrial credential harvesting and cross-tenant theft are separate paths

Industrial credential harvesting and cross-tenant theft are separate paths frkoo · application-secret harvesting Another affiliate · SaaS supply-chain theft 1.8 million distinct APKs 10 EC2 workers: download, decompile, scan secrets Verified credentials Collected in Telegram Initial access for later intrusions Parallel input: GitHub tokens Compromise a SaaS provider Client Downstream customers Client Data extracted from roughly 200 downstream organizations Session-store dump in the same supply-chain case Over 2,100 Azure AD token sets About 34 hours More than 40 tenants Different operators: the APK volume and token-dump results do not come from a single intrusion.
↔ Scroll horizontally to view the full diagram
Left: frkoo’s harvesting infrastructure. Right: another affiliate’s supply-chain case. Branches illustrate fan-out, not the actual number of tenants. [Official] Anthropic

Another SaaS compromise was distinct from both the APK-scanning pipeline and the session-store theft. The actor used cross-site scripting and privilege escalation, then used AI to understand developer and authentication APIs, obtain privileged tokens, construct bulk-export tools and collect data across tenant boundaries. The intrusion reached thousands of downstream organizations.

The same operator claimed legitimate bug-bounty payments of $2,000 and $5,000 from two different targets it had also infiltrated and extorted. Those amounts are claims about payouts, not verified criminal income. In another incident, a stolen developer token led to full administrative control of a victim’s cloud environment in roughly three hours.

Anthropic describes this style of AI use as “vibe hacking.” An operator gives the system a broad objective, such as using a credential to find valuable data. The AI evaluates an unfamiliar environment, writes and runs scripts, summarizes what it finds and iterates until the task is complete. The operator may understand the goal and review the result without mastering every target’s internal configuration.

The source text describes eight recurring lifecycle stages across the cases. They are not a universal strict timeline, and individual intrusions followed different paths.

  1. Sourcing and reconnaissance. Most intrusions began with compromised credentials. The actors also used scanning, vishing, phishing and domain spoofing to obtain access.
  2. Discover. Automated projects mined application binaries, code repositories, client-side code, integrations, credential stores, container images, metadata services, open storage and victim-deployed AI agents for exposed tokens and other access mechanisms.
  3. Validate and qualify. Findings were tested before use or resale through cloud-key validation, purpose-built login checks, production replay, resale grading or offline password recovery.
  4. Expand within the victim environment. A working credential was used to reach more of the victim environment, including secret stores, administrative tokens, CI/CD systems, databases, session tables, signing keys and downstream tenants reached through a vendor’s OAuth identity.
  5. Exfiltration. Material left through six channels: consumer cloud storage, a private network-attached storage system reached over a mesh VPN, Telegram bot streams, staging inside victim cloud environments, C2 channels and bulk API pulls.
  6. Warehouse. Stolen databases, victim-specific loot trees and working credentials were stored for later reuse, resale or delivery through Telegram-backed storefronts.
  7. Mint and persist. Actors created new cloud keys, platform developer keys, forged sessions, two-factor codes or network backdoors so that access could survive credential rotation.
  8. Monetize. The operators resold credentials and access, attempted direct financial theft, extorted victims, claimed bounty income or retained bulk data as leverage.

Figure 2 adds a ninth node, Cover, although the report’s accompanying prose elaborates only the first eight stages and does not provide a separate detailed mechanism for that node. The diagram also makes the lifecycle cyclical rather than terminal: proceeds from credentials fund subsequent discovery, while stolen compute and keys re-enter later operations.

04
GTG-50014 · source figure 2

How stolen resources and proceeds feed another round

How stolen resources and proceeds feed another round Acquire access Monetization and cover Access expansion, exfiltration and retention Source &recon 1 Discover 2 Validate 3 Expand access 4 Exfiltrate 5 Warehouse 6 Mint / persist 7 Monetize 8 Cover 9 Proceeds fund subsequent credential discovery Stolen compute and keys re-enter operations Cover is not elaborated in the source diagram
↔ Scroll horizontally to view the full diagram
Redrawn from the nine-node source figure. Separate return paths reconnect proceeds and stolen compute to their starting stages. This synthesizes cases, not a mandatory intrusion sequence. [Official] Anthropic

Figure 11 further distinguishes four recurring patterns without mapping its affiliate letters to named operators. One pattern begins with a secret embedded in a mobile application and leads to cloud access. A second begins with a copied vendor backup store, then uses the vendor’s OAuth identity to reach downstream customer tenants. A third starts with an administrative token and expands into broader platform access. A fourth begins with prevalidated credential lists and extracts account value for resale or reuse. These are retrospective illustrations of heterogeneous entry points and outcomes, not one common sequence followed by every affiliate.

AI credentials became part of this cycle. One key stolen from a target environment supported roughly three weeks of secondary operations. In every instance described here, the keys came from Anthropic customers’ environments. Anthropic’s own systems were not compromised by these actors.

Original source figures · supporting evidenceExpand source figures

Original figures retain their English text. Open any image at full resolution.

From credentials to extortion
Source · OfficialFigure 1 · From credentials to extortion · Anthropic↗ Open full-resolution figure
Attack lifecycle and AI integration
Source · OfficialFigure 2 · Attack lifecycle and AI integration · Anthropic↗ Open full-resolution figure
Sourcing and reconnaissance
Source · OfficialFigure 3 · Sourcing and reconnaissance · Anthropic↗ Open full-resolution figure
Discover
Source · OfficialFigure 4 · Discover · Anthropic↗ Open full-resolution figure
Validate and qualify
Source · OfficialFigure 5 · Validate and qualify · Anthropic↗ Open full-resolution figure
Expand within the victim environment
Source · OfficialFigure 6 · Expand within the victim environment · Anthropic↗ Open full-resolution figure
Exfiltration channels
Source · OfficialFigure 7 · Exfiltration channels · Anthropic↗ Open full-resolution figure
Warehouse
Source · OfficialFigure 8 · Warehouse · Anthropic↗ Open full-resolution figure
Mint and persist
Source · OfficialFigure 9 · Mint and persist · Anthropic↗ Open full-resolution figure
Monetize
Source · OfficialFigure 10 · Monetize · Anthropic↗ Open full-resolution figure
Distinct affiliate workflows
Source · OfficialFigure 11 · Distinct affiliate workflows · Anthropic↗ Open full-resolution figure
GTG-10007

GTG-10007: parallel research, reconnaissance and collection

GTG-10007 involved Chinese-speaking operators likely based in Changsha. Two identified operators were undergraduate students at a university in Hunan. A state sponsor was not established.

The group targeted roughly fifty organizations across education, retail, energy, technology, healthcare, finance, manufacturing and government. Targeting does not imply successful compromise in every case. Observed outcomes included hundreds of megabytes of student information taken from an education-technology company, access to a retailer’s production environment and citizen records obtained from a Southeast Asian government agency.

The operation divided work into five parallel streams: exploitation and intrusion, reconnaissance of foreign-government networks, reverse engineering of security products, malware development, and construction of collection infrastructure. Lead agents dispatched work to parallel subagents. Target lists, harvested credentials, campaign state and standing instructions persisted between sessions, allowing later work to resume from accumulated context.

One loop focused on firmware and binary analysis. Agents examined the software embedded in appliances and analyzed compiled programs. The workflow loaded appliance firmware and executable files into analysis tools, traced program behavior and formed vulnerability hypotheses. It then produced candidate exploit code and tested it against laboratory copies of the target product, iterating before adding a successful chain to a private portfolio.

The actor validated previously unknown security-product vulnerabilities in its own lab. That result is separate from an appliance workflow that yielded more than a dozen possible zero-day findings in a single month. These were hypotheses about potentially previously unknown flaws. “Possible” and laboratory validation do not amount to vendor confirmation, and these findings were not all classified as confirmed zero-days.

A second loop handled attack-surface and OSINT reconnaissance. It assembled open-source intelligence (OSINT) from publicly accessible material. Agents searched for exposed assets, fingerprinted them, mapped likely entry points and checked them against known vulnerabilities. Each round updated persistent project memory and expanded the scope of later searches.

A third loop operated as a scheduled collection fleet. Thirteen standing AI agents retrieved publicly available military, government, policy and social-media material. Adjacent systems summarized and scored the collected content before delivering it to a portal. Collection from these public sites was not a compromise of those sites.

Hands-on intrusion remained a human role. Operators developed the workflows, consumed their output and engaged during intrusion events. Once access existed, AI enumerated hosts, handled credentials and processed data. Although the automated workflows had global scope, the observed hands-on efforts were concentrated exclusively on victims inside China.

05
GTG-10007

Three concurrent loops, with persistent research and reconnaissance context

Three concurrent loops, with persistent research and reconnaissance context Persistent project memory Target lists · credentials · engagement state · standing instructions 01 · Appliance vulnerability research 02 · Attack-surface reconnaissance 03 · Public-source collection More than a dozenpossible findings / month Firmware andbinaries Decompile and trace Vulnerabilityhypotheses Use research memory Laboratory tests Test product copies Privateportfolio Retain working chains Iterate when unsuccessful Discover exposed assetsBroaden the next search Asset search andprobing Map the exposed surface Qualify entry points Known vulnerabilities Findings expand the next reconnaissance round 13 standing agentsOn a preset schedule Scheduled run No live human input Public sources Publicly accessible Summary andscore Intelligence digests Report portal Deliver digests Collection continues on schedule Laboratory validation ≠ vendor confirmation. Public collection ≠ intrusion into those sites.
↔ Scroll horizontally to view the full diagram
Combines source Figures 12–14. These are the three elaborated loops, not all of the group’s workstreams; human development and hands-on intrusion remain part of the account. [Official] Anthropic
Original source figures · supporting evidenceExpand source figures

Original figures retain their English text. Open any image at full resolution.

Appliance vulnerability research
Source · OfficialFigure 12 · Appliance vulnerability research · Anthropic↗ Open full-resolution figure
Attack-surface and OSINT reconnaissance
Source · OfficialFigure 13 · Attack-surface and OSINT reconnaissance · Anthropic↗ Open full-resolution figure
Scheduled collection fleet
Source · OfficialFigure 14 · Scheduled collection fleet · Anthropic↗ Open full-resolution figure
GTG-50021

The AI supply chain: resale, computing power and cover

API credentials authorize software to call a service. Authenticated session tokens preserve an already established login. In this criminal supply chain, both could move through brokers and fraudulent resellers, be rotated until exhausted and then be replaced with newly stolen access.

Some malicious applications masqueraded as AI tools, including Claude Code. Once installed, they harvested credentials and active sessions from a victim’s device. Resetting a compromised session did not necessarily end the theft because the software could capture newly created sessions and send them to the operator.

GTG-50021, a Russian- and Ukrainian-speaking group, ran one such reseller operation. It advertised discounted Claude access, but secretly sent customer traffic to a different model. Its tooling also stole customers’ Anthropic credentials for resale to other proxy operators. This conduct is attributed specifically to GTG-50021 and does not establish that every reseller follows the same method.

Prompt-injection attacks also targeted AI wrapper services' LiteLLM integrations, which connected applications to different model providers through a common interface. The reported attacks extracted production keys from customer-hosted containers. No new LiteLLM CVE or product-wide compromise was identified in this account.

Anthropic identifies three forms of value in stolen AI access: loot that could be sold, compute paid for by the legitimate account owner and cover because activity appeared under that owner’s credentials. One campaign ran for a month entirely on stolen keys. ShinyHunters affiliates switched workloads to keys obtained from victims, and GTG-50020 first took production credentials from an evaluation environment before continuing its attacks. The resulting recommendation is to treat AI keys and agent integrations with the same seriousness as production credentials and to purchase access only through authorized channels.

06
GTG-50021

Advertised Claude access, redirected traffic and stolen accounts

Advertised Claude access, redirected traffic and stolen accounts GTG-50021 · fraudulent reseller Customer buying access Expects discounted Claude Advertises Claude access Traffic is silently redirected A different AI model Actually receives requests Actual routing Credential-harvestingtooling On the customer’s device Tooling steals credentials Anthropic account credentials Obtained without authorization Other proxy resellers Resell stolen access Persistent harvesting elsewhere in the same section After credentials are reset, a resident harvester can keep collecting new sessions.
↔ Scroll horizontally to view the full diagram
Request traffic and credential theft are separate flows. The persistent-harvesting note comes from other examples in the same section, not a claim about every reseller. [Official] Anthropic
GTG-50020

GTG-50020: from hotel platforms to AI vendors

GTG-50020 was a Russian-speaking, financially motivated actor previously involved in attacks against hotel-booking and financial-technology platforms. In one earlier intrusion, roughly 26 gigabytes of data were stolen and the actor sought $1.5–2.5 million through extortion or sale. Receipt of the payment was not established.

The actor later targeted an AI vendor’s automated evaluation sandbox. By injecting malicious instructions into the evaluation process, it obtained the vendor’s production API keys for multiple model providers. It then continued attacks using victim-funded keys.

A follow-on campaign targeted roughly thirty AI companies in about four days. That number describes targets, not successful breaches. The actor pursued more than a dozen possible paths to a pre-release Claude model, but every attempt failed. The keys came from customer environments; Anthropic's own systems were not compromised.

07
GTG-50020

The evaluation sandbox exposed the customer’s production keys

The evaluation sandbox exposed the customer’s production keys Victim AI vendor’s environment Automated evaluation sandbox Processes external instructions Attacker-supplied input Malicious evaluation instructions Prompt injection Sandbox hands over held credentials Customer’s production AI API keys For multiple model providers Continue attacks with stolenkeys AI usage is billed to the victimaccount Exfiltrate from customer environment About 4 days; roughly 30 AI companiestargeted Targeted does not mean all were compromised Unmet goal: a pre-release Claude model Every attempted access path failed. Anthropic’s own systems were not compromised.
↔ Scroll horizontally to view the full diagram
The boundary identifies the customer environment that held the keys. Follow-on targeting and the unmet objective remain distinct; targeting is not shown as compromise. [Official] Anthropic

The case contained four different workflows. The first was human-directed. A scope file dispatched parallel agents for reconnaissance and exploitation. Findings were retested, viable results were added to an incremental report and the process moved to the next target.

The second used a public, containerized offensive-agent platform against production web applications. Worker agents both probed for flaws and attempted exploitation without human supervision, placing possible findings and obtained credentials into the operator’s workspace. The system therefore combined application testing and active exploitation rather than stopping at vulnerability identification.

The third automated fraudulent account creation. Bots, residential proxies, antidetect browser profiles, CAPTCHA-solving services, inbox polling and automated verification steps produced verified accounts that could be retained for later use.

The fourth intercepted the know-your-customer (KYC) identity checks used by financial and marketplace services. Victims were directed to lookalike domains whose reverse proxy forwarded the genuine verification process. The victim completed real identity verification, while the intermediary captured the resulting authenticated session and documents. The operation stole the verified session; it did not defeat the underlying identity-verification algorithm.

08
GTG-50020 · source figure 18

Identity verification is genuine; the session is intercepted

Identity verification is genuine; the session is intercepted Attacker-controlled intermediary Victim Completes the identitychecks Lookalike verification page andreverse proxy Relays the genuine KYC process Legitimate service Identity verificationcompletes Verification data Verified result Capture verified session and documents Attacker accesses the service fromtheir own device Reuse stolen session The verified session is stolen; the KYC algorithm is not defeated.
↔ Scroll horizontally to view the full diagram
Redraw separates genuine verification, interception at the proxy and reuse of the captured session. [Official] Anthropic
Original source figures · supporting evidenceExpand source figures

Original figures retain their English text. Open any image at full resolution.

Human-directed pentest loop
Source · OfficialFigure 15 · Human-directed pentest loop · Anthropic↗ Open full-resolution figure
Autonomous exploitation pipeline
Source · OfficialFigure 16 · Autonomous exploitation pipeline · Anthropic↗ Open full-resolution figure
Fraud account factory
Source · OfficialFigure 17 · Fraud account factory · Anthropic↗ Open full-resolution figure
KYC session interception
Source · OfficialFigure 18 · KYC session interception · Anthropic↗ Open full-resolution figure
GTG-50029

GTG-50029: one actor and privacy harm at scale

In spring 2026, a single French-speaking individual targeted European political parties, media organizations, think tanks and their SaaS providers. The actor built a Rust-based scanner that searched public containers for exposed API keys. A local proxy layer rotated among validated keys to obscure the resulting traffic.

The campaign exploited a previously undocumented re-installation race condition in the affected sites' WordPress publishing platform. Claude assisted with developing, debugging and testing the technique in a laboratory harness, and it succeeded against at least four websites.

At one political campaign platform, an exposed search interface yielded approximately 140,000 records that included users’ political opinions. Against another target, the actor installed a webshell, a remotely controlled script placed on a web server as a backdoor. An always-loaded WordPress plugin intercepted submitted credentials, and backups were poisoned as well. The report infers that poisoning backups was intended to preserve access by reintroducing the compromise after restoration.

A media intrusion used an injected browser-control script to fingerprint thousands of visitors while seeking editorial staff sessions and credentials. The script communicated through a C2 framework operated by the actor.

The actor’s signature platform, fafsearch, combined pre-existing breach dumps with data from the actor’s own intrusions. It normalized and ranked records, tested the system and packaged it for containerized deployment. The resulting service contained tens of millions of rows. Those rows were not all freshly stolen by this individual. The entire platform was built by one person.

09
GTG-50029

Two data sources converge into a person-searchable repository

Two data sources converge into a person-searchable repository Pre-existing breachdatabases Not all newly stolen Data stolen in the actor’sintrusions From the actor’s targets Normalize andcross-reference Identity and phone numbersMatching and ranking fafsearch Search by name Tens of millions of rows A platform built by one person Campaign scope and exfiltration (GTG-50029) 42 tracked targets Internal access to at least 14 Estimated 12 to 26 GB
↔ Scroll horizontally to view the full diagram
The repository combines prior leaks and the actor’s own theft. The lower figures describe campaign scope, not the provenance of every row in the platform. [Official] Anthropic

Across 42 tracked target entities, the actor obtained internal access to at least 14. The estimated volume of exfiltrated database dumps was 12 to 26 GB. The material included political donor and membership information, a 15,000-message mailbox, student applications involving minors and payment-provider data. The actor also established live credential interception. These figures describe different observed effects and do not imply that every system reached yielded its entire database.

Synthesis

Diffusion, autonomy and human decisions

Anthropic draws two broad developments from these unconnected campaigns. The first is diffusion. Similar working patterns appeared across different motivations, regions and levels of prior capability. Public frameworks reduced the need to build orchestration from the ground up, while stolen credentials and AI access supported a criminal market around the workflows. Familiar entry methods coexisted with both known vulnerabilities and research into previously unknown flaws. The second is a spectrum of autonomy. At one end, Claude acted conversationally during development. Further along, humans directed commands while AI operated against victim environments. At the far end, parallel agents ran reconnaissance, exploitation and theft for extended periods. GTG-10007 scheduled public-source collection without a person in the loop. GTG-20006 used scheduled jobs for token renewal and cloud collection as well as human-directed intrusion steps.

Appendix A shows how actors packaged work into reusable skills. The categories cover security engineering, C2 and phishing infrastructure operation, reconnaissance and credential-access roles, native Windows development, frontend and control-panel work, iOS vulnerability research, and memory that preserved previous findings and dead ends. These are reusable task instructions, not a measured effectiveness benchmark or an implementation guide.

Humans retained control over decisions about targets, monetization and review. Several serious compromises arose from operations in which a person directed every step. Anthropic’s economic judgment is that AI changed the labor and unit cost of reconnaissance, exploit research, tooling and data processing; this is not a measured return-on-investment calculation. Work that once required several specialized roles could be divided among agents, retained across sessions and repeated against multiple environments, while human operators continued to decide what the operation was for. The company therefore separates autonomy from severity:

Second, autonomy and harm are separate axes: Autonomy multiplies the scale and speed of an operation, and reduces operating costs and complexity, but severity is still determined by a multitude of factors.
Anthropic · Synthesis
Original source figures · supporting evidenceExpand source figures

Original figures retain their English text. Open any image at full resolution.

Skill breakdown
Source · OfficialFigure 19 · Skill breakdown · Anthropic↗ Open full-resolution figure
Official sources

Sources and original material

Cases, attribution and statistics follow Anthropic’s investigation. This article covers cyber operations only.

Official Claude Code overview, for the product's role as a coding tool.
Official Microsoft identity-service description, for the Azure AD first-use explanation.