Advisories › ACVE-2026-0529
ACVE-2026-0529
GTG-20006 used Claude-driven workflows to automate reconnaissance, phishing, credential harvesting, malware evasion and exfiltration against more than 20 organisations.
Exposure
- Evidence
- Real use · vendor report
Anthropic fixed: Anthropic says it disrupted the activity and strengthened safeguards. — www.anthropic.com - Model
- Claude Haiku, Sonnet or Opus; exact model not stated — confirmed, www.anthropic.com
- Goal
- Conduct cyber espionage against government, defense and related organisations — confirmed, www.anthropic.com
- Tools and settings
- AI-driven workflows for reconnaissance, phishing, malware management and exfiltration — confirmed, www.anthropic.com
- Approval
- The workflows automated repeated campaign steps; human operators set targets and reviewed results — confirmed, www.anthropic.com
- Input controlled by
- operator
- What the agent does
- The agent runs reconnaissance, phishing, credential harvesting and exfiltration workflows against external targets.
- Harm
- data-exfiltration
- Reach
- Victim mailboxes, accounts, networks and identity records — confirmed, www.anthropic.com (the network, private repositories, cloud credentials)
- Condition
- When the operator delegated repeated kill-chain stages to AI-driven workflows — confirmed, www.anthropic.com
- Scale
- More than twenty organisations were targeted — not stated systems, www.anthropic.com
Reproducibility: partial (model availability not checked (no registry reference); trigger not published)
- Status
- Unverified
- Kind
- Behavioural
- Modified
- 2026-09-25
- Aliases
- No CVE assigned — No code defect: the harm arose from an attacker using Claude to decompose offensive operations.
- Affected
- AgentHarness: claude — all versions
- Harness/product
- claude
- Classes
- credential-theft; data-exfiltration; over-privileged-combination; CWE-522; CWE-359; CWE-693
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
Description
Threat
user · unsafe-default · exfiltration
What
Anthropic says a suspected Russian state-nexus operator used Claude-driven workflows across the cyber kill chain, including reconnaissance, phishing infrastructure, credential harvesting, malware evasion, account compromise and data exfiltration. The operation targeted more than 20 organisations.
Detection
Anthropic identified and disrupted the activity. Recorded from Anthropic's September 2026 threat report. Not recreated in a lab.
Fix
Keep agent actions against external networks behind authorization and isolate credentials, mailboxes and customer data from autonomous workflows.
Fix
The operator was the attacker, so the control that protects victims is the model provider's: Anthropic disrupted the operation and strengthened safeguards.
- Reconfigure
anthropic.safeguards to strengthened after the operation was disrupted. Shipped by Anthropic: it disrupted GTG-20006 and strengthened safeguards. Owner: model-provider
Report a problemJSON