ACVEAgent configuration vulnerability registry

ACVE-2026-0525

Breached at least four European websites, exfiltrated about 140,000 political-opinion records and targeted credentials and reader sessions: GTG-50029 hacktivists with Claude in an agent framework.

Exposure

Reproducibility: partial (model availability not checked (no registry reference); trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

Claims on this page have not been checked against primary sources.

Description

Threat

user · unsafe-default · exfiltration

What

Anthropic says a French-speaking actor used Claude and sub-agents to target European political parties, media, think tanks and their service providers. The campaign compromised at least four websites, including a political campaign platform from which about 140,000 records containing political opinions were exfiltrated.

Detection

Anthropic identified and disrupted the campaign. Recorded from Anthropic's September 2026 threat report. Not recreated in a lab.

Fix

Treat agent frameworks and exposed API keys as privileged infrastructure, limit access to political and identity data, and monitor automated multi-site activity.

Fix

The operator was the attacker, so the control that protects victims is the model provider's: Anthropic disrupted the campaign and strengthened safeguards.

  • Reconfigure anthropic.safeguards to strengthened after the campaign was disrupted. Shipped by Anthropic: it disrupted GTG-50029 and strengthened safeguards. Owner: model-provider

References

REPORT

Report a problemJSON