Claude Code
Incidents implicated systems
Incidente 126334 Reportes
Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage
2025-11-13
Anthropic reportedly identified a cyber espionage campaign in which a purported Chinese state-linked group, designated GTG-1002 by Anthropic, allegedly jailbroke Claude Code and used it to automate 80–90% of multi-stage intrusions. The AI reportedly independently performed reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data extraction across roughly 30 targets before the activity was detected and blocked.
MásIncidente 16805 Reportes
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package
2026-02-17
An unknown actor reportedly exploited prompt injection in Cline's Claude-powered GitHub issue-triage workflow and a GitHub Actions cache-poisoning path to obtain publication credentials. On February 17, 2026, a still-valid npm token was used to publish unauthorized cline@2.3.0, which installed OpenClaw without user intent. Cline said OpenClaw was non-malicious; it deprecated the release and revoked the token that day, while reporting that it found no evidence of user-data exposure.
MásIncidente 17234 Reportes
Anthropic's Claude Code AI Coding Tool Reportedly Used Hidden Unicode Markers to Classify Custom API Routing
2026-04-02
Researchers found that Anthropic's Claude Code AI coding tool classified custom API endpoint hostnames and two system timezones, encoding the results in system prompts with visually similar Unicode apostrophes and altered date separators. Anthropic said the mechanism was an anti-reseller and anti-distillation experiment launched in March and removed it after disclosure.
MásIncidente 12013 Reportes
Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales
2025-08-27
In August 2025, Anthropic published a threat intelligence report detailing multiple misuse cases of its Claude models. Documented abuses included a large-scale extortion campaign using Claude Code against at least 17 organizations, fraudulent remote employment schemes linked to North Korean operatives, and the development and sale of AI-generated ransomware. Anthropic banned the accounts, implemented new safeguards, and shared indicators with authorities.
MásEntidades relacionadas
Otras entidades que están relacionadas con el mismo incidente. Por ejemplo, si el desarrollador de un incidente es esta entidad pero el implementador es otra entidad, se marcan como entidades relacionadas.
Entidades relacionadas
Anthropic
Incidentes involucrados como desarrollador e implementador
Incidents involved as Developer
State-linked operator using autonomous AI-enabled intrusion workflows
Incidents involved as Deployer
Software developers
Afectado por Incidentes
- Incidente 16805 Report
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package
- Incidente 16763 Report
Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work
Incidents involved as Deployer
AI agent system users
Afectado por Incidentes
- Incidente 16763 Report
Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work
- Incidente 17191 Report
Anthropic's Claude Code AI Agent Reportedly Deleted About 48,000 Live Project Files and Version-Control History During Software Repair
Incidents involved as Deployer
Threat actors
Incidents involved as Deployer
- Incidente 16805 Report
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package
- Incidente 16871 Report
Anthropic-Designated GTG-87001 Weapons Cell in Northern Yemen Reportedly Used Claude Code to Develop Missile Guidance Software
AI coding assistant users
Afectado por Incidentes
- Incidente 17234 Report
Anthropic's Claude Code AI Coding Tool Reportedly Used Hidden Unicode Markers to Classify Custom API Routing
- Incidente 17191 Report
Anthropic's Claude Code AI Agent Reportedly Deleted About 48,000 Live Project Files and Version-Control History During Software Repair