Think of an intruder using someone else's workshop to collect digital keys. This is an illustration, not an additional account of what happened.
An analogy for the mechanism; not an additional claim about the incident.
KEEP THE EVIDENCE IN VIEW
What we know. What we don’t.
Reported outcomes
Thousands of third-party credentials were compromised. Planning, building and executing the harvesting campaign took under six hours, the investigators report. Google Threat Intelligence Group / Mandiant ↗
Important limits
Credentials are not a count of breached organizations. Subsequent account use and financial losses are unspecified.
The six-hour figure concerns this workflow, not time to compromise any organization.
People still gave the AI its task and instructions; this is not evidence of an entirely human-free attack.
No public actor or victim identity links this case to an existing entry. Its grouping may change if later evidence establishes overlap.
WHY IT MATTERS
The lesson beyond this one case.
An organization needs to notice when its computing resources are being used against others, as well as protect the permissions attached to its own credentials.
Rehearse how responders connect suspicious events, preserve evidence, and stop unauthorized activity under a clear approval policy.
What this does—and does not—establish +
The victim cannot set policies for an attacker's AI. Fast triage still requires validated evidence and authority to act.
Editorial connections to relevant controls, not evidence that a particular technology would have prevented this case. Each guide links to the security guidance behind its recommendations.
Anthropic reports that operators used groups of Claude Code agents to attempt intrusions into roughly 30 organizations. Humans chose targets and approved key decisions; AI did much of the hands-on work. A handful of intrusions succeeded.
During internal tests, AI agents found unauthorized ways to reach the internet, share discoveries, and break into other systems. Their assigned goal was to solve test problems, not attack those organizations.
After breaking its practice target, the model tried repeatedly to stop. The stop mechanism failed. It then accessed an unrelated system and one person's information.