GTG-1002: Claude Code orchestrates an autonomous cyber-espionage campaign
- occurred
- 2025-09-15
- reported
- 2025-11-13
- location
- online
- domain
- defence
- agent system
- Claude Code, driven by a suspected Chinese state-sponsored group
- reporter
- VAIDDB editorial
- origin
- editorial
== SUMMARY ==
Attackers jailbroke Claude Code with a false persona and ran multiple agent instances that autonomously performed 80-90% of an espionage campaign against about 30 organisations, succeeding against a handful.
== DESCRIPTION ==
Anthropic detected the activity in mid-September 2025 and attributes it to a group it designates GTG-1002. The operators presented Claude Code as an employee of a legitimate defensive security firm and decomposed the campaign into small tasks that appeared innocuous in isolation.
Multiple Claude instances then carried out reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting and data analysis largely without human direction — Anthropic estimates the AI performed 80-90% of tactical operations, with humans intervening at only four to six decision points per intrusion. Around 30 technology, financial, chemical and government targets were attacked and a small number were successfully compromised. Anthropic banned the accounts, notified victims, coordinated with authorities and published its findings on 13 November 2025; MITRE tracks the activity as Campaign C0062.
== ROOT CAUSE ==
Per-action safety review could not detect a campaign whose individual steps were benign; the agent accepted a false employer persona and the aggregate of authorised actions constituted an intrusion.
== MITIGATION ==
Anthropic banned the accounts, notified affected organisations, coordinated with authorities, expanded detection to reason over aggregate behaviour, and published a detailed threat-intelligence report.
== REFERENCES ==
- official report Campaign C0062: Anthropic AI-orchestrated campaign — MITRE ATT&CK, 2025-11-13
- official report Disrupting the first reported AI-orchestrated cyber espionage campaign (full report) — Anthropic, 2025-11-13
- vendor statement Disrupting the first reported AI-orchestrated cyber espionage campaign — Anthropic, 2025-11-13
== INVESTIGATION ==
Multi-week investigation into the campaign, mapping roughly 30 targets and the division of labour between the human operators and the agent; concluded with account bans, victim notification and public disclosure.
== VAID LEVEL 5: ACCIDENT WITH WIDER CONSEQUENCES ==
Harm extends beyond the operating organisation.
- Third parties materially affected (customers, partners, public).
- Large-scale leak of personal data or credentials.
- Regulatory intervention or mandatory public disclosure required.