Evidence over alarm
← Back to the incident library
Malicious useGTG-1002 / Reported by Anthropic

An espionage operation put AI agents to work across targets

Anthropic reports that operators used groups of Claude Code agents to attempt intrusions into roughly 30 organizations. Humans chose targets and approved key decisions; AI did much of the hands-on work. A handful of intrusions succeeded.

Source: Anthropic
ACTIVITYSeptember 2025; detected mid-month
PUBLICLY DISCLOSEDNov 13, 2025
THE AI’S ROLEAI agents coordinate work; humans supervise
THE 10-SECOND TAKEAWAY

The human sets the goal. AI carries more of the workload.

HOW IT WORKED

Follow the chain.

An explanation, not a technical reproduction.
Human operators
Chosen targets
Assigned work
SIMPLIFIED VIEW · 1 / 3
STEP 01

People set the objective

Human operators picked organizations and put an automated system in charge of assigning work.

Anthropic
Move through the story at your own pace.
1 / 3
THINK OF IT THIS WAY

Picture a manager assigning a job to several assistants, who divide it into smaller tasks and return for important approvals. Automation changes how much work happens between those approvals; it does not make every result correct.

An analogy for the mechanism; not an additional claim about the incident.
KEEP THE EVIDENCE IN VIEW

What we know.
What we don’t.

Reported outcomes

Anthropic validated a handful of intrusions among roughly 30 targets and reports theft of credentials and sensitive information. Anthropic

The provider estimates AI independently performed 80–90% of the tactical work. That is an estimate of work delegated, not an attack success rate. Anthropic

Important limits

The figures and Chinese state sponsorship attribution are Anthropic's assessment; its visibility is limited to Claude usage.

Claude sometimes invented credentials or treated public information as stolen secrets. Human supervision and validation were still required.

WHY IT MATTERS

The lesson beyond
this one case.

A team that delegates more of the routine work may be able to pursue more targets. The practical concern is how much an operator can attempt between human decisions, alongside whether those attempts succeed.

What happened in response? +

Anthropic banned accounts, notified affected organizations where appropriate, coordinated with authorities, and expanded its detection measures. Anthropic

FROM THE INCIDENT TO THE DEFENSE

What could help
an organization?

In Anthropic's account, humans selected targets while groups of AI agents performed much of the intrusion work.

Software

Shorten the time to a verified fix

Use code analysis and testing to find exposed weaknesses, then review, deploy, and verify repairs; AI can assist with investigation and proposed changes.

What this does—and does not—establish

An AI-generated repair may be wrong or incomplete. Verification must check both security and normal application behavior.

Cloud

Contain each compromised account

Narrow account permissions and separate systems so that a stolen credential provides less access to other services and sensitive records.

What this does—and does not—establish

This limits possible spread; it does not establish that the specific intrusions in the report would have been prevented.

Security operations

Join the evidence quickly

Connect application, identity, and data-access records so investigators can recognize related actions and act before further access occurs.

What this does—and does not—establish

Targets generally cannot see the attacker's AI instructions. Detection must work from activity visible in their own systems.

Editorial connections to relevant controls, not evidence that a particular technology would have prevented this case. Each guide links to the security guidance behind its recommendations.

Explore the full AI security framework
TRACE IT TO THE SOURCE

Read the evidence.

Explore more original accounts in the source report library ↗.

These are source-reported findings. An independent assessment, when available, is labeled explicitly.

01
Disrupting the first reported AI-orchestrated cyber espionage campaignAnthropic · Nov 13, 2025 · provider investigation
02
Disrupting the first reported AI-orchestrated cyber espionage campaign — full reportAnthropic · Nov 13, 2025 · provider technical report

Reviewed Sep 10, 2026 · Editorial methodology · Structured data