Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse

Incident 1263: Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Description: Anthropic reportedly identified a cyber espionage campaign in which a purported Chinese state-linked group, designated GTG-1002 by Anthropic, allegedly jailbroke Claude Code and used it to automate 80–90% of multi-stage intrusions. The AI reportedly independently performed reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data extraction across roughly 30 targets before the activity was detected and blocked.
Editor Notes: Anthropic's full report can be read here: https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf. The reported Chinese state-sponsored deployer has been designated GTG-1002 by Anthropic. They reportedly detected the activity sometime in mid-September 2025. The incident ID date of 11/13/2025 corresponds to the publication of their initial findings.

Tools

New ReportNew ReportNew ResponseNew ResponseDiscoverDiscoverView HistoryView History

Entities

View all entities
Alleged: Anthropic developed an AI system deployed by Unknown Chinese state-sponsored entity , State-linked operator using autonomous AI-enabled intrusion workflows and GTG-1002, which harmed Targets of autonomous AI-enabled intrusion operations , National security and intelligence stakeholders and Entities targeted by GTG-1002.
Alleged implicated AI systems: Open-source penetration testing tools , Model Context Protocol (MCP) , MCP-integrated toolchain , GTG-1002's autonomous orchestration framework , Claude Code , Autonomous AI-enabled intrusion orchestration framework and Agentic AI system

Incident Stats

Incident ID
1263
Report Count
33
Incident Date
2025-11-13
Editors
Daniel Atherton

Incident Reports

Reports Timeline

+7
Disrupting the first reported AI-orchestrated cyber espionage campaign
+19
Anthropic details cyber espionage campaign orchestrated by AI
Anthropic Unveils First AI-Driven Cyber Espionage OperationAnthropic: China-backed hackers launch first large-scale autonomous AI cyberattack+3
Claude’s Cyber Shadow: Inside Anthropic’s Claim of AI-Driven Espionage and Rising Doubts
Loading...
Disrupting the first reported AI-orchestrated cyber espionage campaign

Disrupting the first reported AI-orchestrated cyber espionage campaign

anthropic.com

Loading...
Chinese Hackers Used Anthropic’s AI to Automate Cyberattacks

Chinese Hackers Used Anthropic’s AI to Automate Cyberattacks

wsj.com

Loading...
Chinese spies told Claude to break into about 30 critical orgs. Some attacks succeeded

Chinese spies told Claude to break into about 30 critical orgs. Some attacks succeeded

theregister.com

Loading...
Anthropic Warns Cyberattack Barriers Have Fallen as AI Capabilities Accelerate

Anthropic Warns Cyberattack Barriers Have Fallen as AI Capabilities Accelerate

news.bitcoin.com

Loading...
China Can’t Even Hack America Without Importing American Technology First

China Can’t Even Hack America Without Importing American Technology First

dailycaller.com

Loading...
Chinese hackers used Anthropic's AI agent to automate spying

Chinese hackers used Anthropic's AI agent to automate spying

axios.com

Loading...
Hackers use Anthropic’s AI model Claude once again

Hackers use Anthropic’s AI model Claude once again

theverge.com

Loading...
Anthropic details cyber espionage campaign orchestrated by AI

Anthropic details cyber espionage campaign orchestrated by AI

artificialintelligence-news.com

Loading...
Anthropic warns state-linked actor abused its AI tool in sophisticated espionage campaign

Anthropic warns state-linked actor abused its AI tool in sophisticated espionage campaign

cybersecuritydive.com

Loading...
Chinese Hackers Use Anthropic's AI to Launch Automated Cyber Espionage Campaign

Chinese Hackers Use Anthropic's AI to Launch Automated Cyber Espionage Campaign

thehackernews.com

Loading...
Chinese state hackers used Anthropic AI systems in dozens of attacks

Chinese state hackers used Anthropic AI systems in dozens of attacks

therecord.media

Loading...
Researchers question Anthropic claim that AI-assisted attack was 90% autonomous

Researchers question Anthropic claim that AI-assisted attack was 90% autonomous

arstechnica.com

Loading...
Anthropic claims of Claude AI-automated cyberattacks met with doubt

Anthropic claims of Claude AI-automated cyberattacks met with doubt

bleepingcomputer.com

Loading...
Chinese hackers hijack Anthropic AI in 1st 'large scale' cyberattack

Chinese hackers hijack Anthropic AI in 1st 'large scale' cyberattack

upi.com

Loading...
The age of AI-run cyberattacks has begun

The age of AI-run cyberattacks has begun

vox.com

Loading...
Anthropic Has Some Key Advice for Businesses in the Aftermath of a Massive AI Cyberattack

Anthropic Has Some Key Advice for Businesses in the Aftermath of a Massive AI Cyberattack

inc.com

Loading...
Chinese State Hackers Just Pulled Off The World’s First Autonomous AI Hack

Chinese State Hackers Just Pulled Off The World’s First Autonomous AI Hack

swarajyamag.com

Loading...
Tech giant Anthropic reveals Chinese state hackers deployed AI for autonomous attacks

Tech giant Anthropic reveals Chinese state hackers deployed AI for autonomous attacks

tag24.com

Loading...
Chinese Hackers Weaponize Claude AI to Execute First Autonomous Cyber Espionage Campaign at Scale

Chinese Hackers Weaponize Claude AI to Execute First Autonomous Cyber Espionage Campaign at Scale

thecyberexpress.com

Loading...
Chinese State-Sponsored GTG-1002 Leverages Claude AI and MCP for Cyberespionage Targeting Tens of Organizations

Chinese State-Sponsored GTG-1002 Leverages Claude AI and MCP for Cyberespionage Targeting Tens of Organizations

technadu.com

Loading...
AI firm claims it stopped Chinese state-sponsored cyber-attack campaign

AI firm claims it stopped Chinese state-sponsored cyber-attack campaign

theguardian.com

Loading...
A.I. Agents Usher in a New Era of Cyberespionage

A.I. Agents Usher in a New Era of Cyberespionage

nytimes.com

Loading...
China’s ‘autonomous’ AI-powered hacking campaign still required a ton of human work

China’s ‘autonomous’ AI-powered hacking campaign still required a ton of human work

cyberscoop.com

Loading...
Anthropic warns of AI-driven hacking campaign linked to China

Anthropic warns of AI-driven hacking campaign linked to China

apnews.com

Loading...
Anthropic says Chinese hackers used its Claude AI chatbot in cyberattacks

Anthropic says Chinese hackers used its Claude AI chatbot in cyberattacks

cbsnews.com

Loading...
Anthropic reports that "Claude" was exploited by Chinese government-affiliated attackers

Anthropic reports that "Claude" was exploited by Chinese government-affiliated attackers

itmedia.co.jp

Loading...
AI doesn't just assist cyberattacks anymore - now it can carry them out

AI doesn't just assist cyberattacks anymore - now it can carry them out

zdnet.com

Loading...
Anthropic Unveils First AI-Driven Cyber Espionage Operation

Anthropic Unveils First AI-Driven Cyber Espionage Operation

forklog.com

Loading...
Anthropic: China-backed hackers launch first large-scale autonomous AI cyberattack

Anthropic: China-backed hackers launch first large-scale autonomous AI cyberattack

securityaffairs.com

Loading...
Claude’s Cyber Shadow: Inside Anthropic’s Claim of AI-Driven Espionage and Rising Doubts

Claude’s Cyber Shadow: Inside Anthropic’s Claim of AI-Driven Espionage and Rising Doubts

webpronews.com

Loading...
Anthropic uncovers first large-scale AI-orchestrated cyber espionage campaign using Claude Code

Anthropic uncovers first large-scale AI-orchestrated cyber espionage campaign using Claude Code

edtechinnovationhub.com

Loading...
Anthropic Alleges Chinese Hackers Used AI for Massive Cyber Espionage

Anthropic Alleges Chinese Hackers Used AI for Massive Cyber Espionage

opentools.ai

Loading...
AI-driven cyber attacks are becoming a reality – Anthropic reports large-scale activity

AI-driven cyber attacks are becoming a reality – Anthropic reports large-scale activity

japan.zdnet.com

Loading...
Disrupting the first reported AI-orchestrated cyber espionage campaign
anthropic.com · 2025

We recently argued that an inflection point had been reached in cybersecurity: a point at which AI models had become genuinely useful for cybersecurity operations, both for good and for ill. This was based on systematic evaluations showing …

Loading...
Chinese Hackers Used Anthropic’s AI to Automate Cyberattacks
wsj.com · 2025

China's state-sponsored hackers used artificial-intelligence technology from Anthropic to automate break-ins of major corporations and foreign governments during a September hacking campaign, the company said Thursday.

The effort focused on…

Loading...
Chinese spies told Claude to break into about 30 critical orgs. Some attacks succeeded
theregister.com · 2025

Chinese cyber spies used Anthropic's Claude Code AI tool to attempt digital break-ins at about 30 high-profile companies and government organizations -- and the government-backed snoops "succeeded in a small number of cases," according to a…

Loading...
Anthropic Warns Cyberattack Barriers Have Fallen as AI Capabilities Accelerate
news.bitcoin.com · 2025

Anthropic, the AI firm behind Claude, says its internal evaluations and threat-intelligence work show a decisive shift in cyber capability development. According to a recently released investigation, cyber capabilities among AI systems have…

Loading...
China Can’t Even Hack America Without Importing American Technology First
dailycaller.com · 2025

A Chinese state-backed crew leaned on U.S.-made AI to run one of the most advanced espionage hacks on record, using Anthropic's Claude Code to automate as much as 90% of the grunt work, according to a November report from the company's thre…

Loading...
Chinese hackers used Anthropic's AI agent to automate spying
axios.com · 2025

Suspected Chinese operators used Anthropic's AI coding tool to target about 30 global organizations --- and had success in several cases, the company said Thursday.

Why it matters: This is the first documented case of a foreign government u…

Loading...
Hackers use Anthropic’s AI model Claude once again
theverge.com · 2025

Anthropic announced on Thursday that Chinese state-backed hackers used the company's AI model Claude to automate roughly 30 attacks on corporations and governments during a September campaign, according to reporting from the Wall Street Jou…

Loading...
Anthropic details cyber espionage campaign orchestrated by AI
artificialintelligence-news.com · 2025

Security leaders face a new class of autonomous threat as Anthropic details the first cyber espionage campaign orchestrated by AI.

In a report released this week, the company’s Threat Intelligence team outlined its disruption of a sophistic…

Loading...
Anthropic warns state-linked actor abused its AI tool in sophisticated espionage campaign
cybersecuritydive.com · 2025

Anthropic said a suspected state-linked hacker manipulated one of its agentic AI-based coding tools to conduct a sophisticated espionage campaign in September against about 30 major organizations across the globe, according to a blog post p…

Loading...
Chinese Hackers Use Anthropic's AI to Launch Automated Cyber Espionage Campaign
thehackernews.com · 2025

State-sponsored threat actors from China used artificial intelligence (AI) technology developed by Anthropic to orchestrate automated cyber attacks as part of a "highly sophisticated espionage campaign" in mid-September 2025.

"The attackers…

Loading...
Chinese state hackers used Anthropic AI systems in dozens of attacks
therecord.media · 2025

An alarming study from artificial intelligence giant Anthropic found that a Chinese espionage group used the company's AI systems to handle the majority of tasks during cyberattacks on about 30 entities --- several of which were successfull…

Loading...
Researchers question Anthropic claim that AI-assisted attack was 90% autonomous
arstechnica.com · 2025

Researchers from Anthropic said they recently observed the "first reported AI-orchestrated cyber espionage campaign" after detecting China-state hackers using the company's Claude AI tool in a campaign aimed at dozens of targets. Outside re…

Loading...
Anthropic claims of Claude AI-automated cyberattacks met with doubt
bleepingcomputer.com · 2025

Anthropic reports that a Chinese state-sponsored threat group, tracked as GTG-1002, carried out a cyber-espionage operation that was largely automated through the abuse of the company's Claude Code AI model.

However, Anthropic's claims imme…

Loading...
Chinese hackers hijack Anthropic AI in 1st 'large scale' cyberattack
upi.com · 2025

Nov. 14 (UPI) -- Tech giant Anthropic confirmed Chinese actors managed to seize control of its AI model Claude to execute a large cyberattack with little human interaction.

On Thursday, Anthropic officials said in a blog post in mid-Septemb…

Loading...
The age of AI-run cyberattacks has begun
vox.com · 2025

Menu planning, therapy, essay writing, highly sophisticated global cyberattacks: People just keep coming up with innovative new uses for the latest AI chatbots.

An alarming new milestone was reached this week when the artificial intelligenc…

Loading...
Anthropic Has Some Key Advice for Businesses in the Aftermath of a Massive AI Cyberattack
inc.com · 2025

Safety-focused AI startup Anthropic says that a "Chinese state-sponsored group" used Claude Code, the company's agentic coding tool, to perform a highly advanced cyberattack on roughly 30 entities---and in some cases even succeeded in steal…

Loading...
Chinese State Hackers Just Pulled Off The World’s First Autonomous AI Hack
swarajyamag.com · 2025
  • The hackers used AI to handle about 80 to 90 per cent of the attack, needing humans only a few times for four to six key decisions in each campaign.

Artificial intelligence firm Anthropic has disclosed what it describes as the first docum…

Loading...
Tech giant Anthropic reveals Chinese state hackers deployed AI for autonomous attacks
tag24.com · 2025

Washington DC - Artificial intelligence company Anthropic has detected and disrupted what it described as the first documented cyber espionage campaign conducted largely autonomously by AI, marking a significant escalation in machine learni…

Loading...
Chinese Hackers Weaponize Claude AI to Execute First Autonomous Cyber Espionage Campaign at Scale
thecyberexpress.com · 2025

The AI executed thousands of requests per second.

That physically impossible attack tempo, sustained across multiple simultaneous intrusions targeting 30 global organizations, marks what Anthropic researchers now confirm as the first docume…

Loading...
Chinese State-Sponsored GTG-1002 Leverages Claude AI and MCP for Cyberespionage Targeting Tens of Organizations
technadu.com · 2025

Key Takeaways

  • **AI-orchestrated attacks: **Chinese state-sponsored group GTG-1002 used Anthropic's Claude and the MCP for highly autonomous cyberespionage operations.
  • Multi-phase operations: The campaign targeted around 30 significant orga…
Loading...
AI firm claims it stopped Chinese state-sponsored cyber-attack campaign
theguardian.com · 2025

A leading artificial intelligence company claims to have stopped a China-backed “cyber espionage” campaign that was able to infiltrate financial firms and government agencies with almost no human oversight.

The US-based Anthropic said its c…

Loading...
A.I. Agents Usher in a New Era of Cyberespionage
nytimes.com · 2025

Andrew here. Breaking: Doug McMillon, Walmart's C.E.O., will retire and be succeeded by John Furner, who has been with the company for more than 30 years.

We often talk about the transformative possibilities of artificial intelligence. But …

Loading...
China’s ‘autonomous’ AI-powered hacking campaign still required a ton of human work
cyberscoop.com · 2025

Anthropic made headlines Thursday when it released research claiming that a previously unknown Chinese state-sponsored hacking group used the company's Claude AI generative AI product to breach at least 30 different organizations.

According…

Loading...
Anthropic warns of AI-driven hacking campaign linked to China
apnews.com · 2025

WASHINGTON (AP) --- A team of researchers has uncovered what they say is the first reported use of artificial intelligence to direct a hacking campaign in a largely automated fashion.

The AI company Anthropic said this week that it disrupte…

Loading...
Anthropic says Chinese hackers used its Claude AI chatbot in cyberattacks
cbsnews.com · 2025

Anthropic said Thursday that Chinese hackers used its artificial intelligence technology in what the company believes is the first cyberespionage operation largely carried out using AI.

Anthropic said the cybercriminals used its popular cha…

Loading...
Anthropic reports that "Claude" was exploited by Chinese government-affiliated attackers
itmedia.co.jp · 2025
AI Translated

On November 13th (local time), Anthropic announced that a Chinese government-sponsored attacker group had exploited its AI model "Claude" to automate approximately 30 attacks against companies and governments. The espionage activity was det…

Loading...
AI doesn't just assist cyberattacks anymore - now it can carry them out
zdnet.com · 2025

ZDNET's key takeaways

  • Anthropic documented a large-scale cyberattack using AI.
  • Anthropic says that a Chinese state-sponsored group is to blame.
  • The attack may be the first case of its kind. 

The first large-scale cyberattack campaign lev…

Loading...
Anthropic Unveils First AI-Driven Cyber Espionage Operation
forklog.com · 2025

In September, the threat analysis team at startup Anthropic identified and disrupted an unprecedented AI-driven cyber espionage campaign.

Experts believe the operation, named GTG-1002, was likely orchestrated by a Chinese state entity.

The …

Loading...
Anthropic: China-backed hackers launch first large-scale autonomous AI cyberattack
securityaffairs.com · 2025

China-linked actors used Anthropic's AI to automate and run cyberattacks in a sophisticated 2025 espionage campaign using advanced agentic tools.

China-linked threat actors used Anthropic's AI to automate and execute cyberattacks in a highl…

Loading...
Claude’s Cyber Shadow: Inside Anthropic’s Claim of AI-Driven Espionage and Rising Doubts
webpronews.com · 2025

In a revelation that has sent shockwaves through the cybersecurity and AI communities, Anthropic, the company behind the advanced AI model Claude, announced it had disrupted what it describes as the first large-scale cyber-espionage campaig…

Loading...
Anthropic uncovers first large-scale AI-orchestrated cyber espionage campaign using Claude Code
edtechinnovationhub.com · 2025

Anthropic has released an extensive account of what it describes as the first confirmed case of a large-scale cyber espionage campaign conducted primarily by an AI system rather than human hackers.

The disclosure follows a ten-day investiga…

Loading...
Anthropic Alleges Chinese Hackers Used AI for Massive Cyber Espionage
opentools.ai · 2025

In a groundbreaking revelation, Anthropic has accused a Chinese state-sponsored hacking group of deploying its AI model to orchestrate autonomous cyberattacks on an unprecedented scale. The group's AI-driven capabilities allowed them to exe…

Loading...
AI-driven cyber attacks are becoming a reality – Anthropic reports large-scale activity
japan.zdnet.com · 2025
AI Translated

AIID editor's note: This report is accessible to members on the second page. Please consult the original source.

The first large-scale cyberattack campaign has been documented that leverages artificial intelligence (AI) as more than just a …

Variants

A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?

Similar Incidents

Selected by our editors

Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Aug 2025 · 3 reports
Previous IncidentNext Incident

Similar Incidents

Selected by our editors

Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Aug 2025 · 3 reports

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • e59d373