ACVEAgent configuration vulnerability registry

ACVE-2026-0529

GTG-20006 used Claude-driven workflows to automate reconnaissance, phishing, credential harvesting, malware evasion and exfiltration against more than 20 organisations.

Exposure

Reproducibility: partial (model availability not checked (no registry reference); trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

Claims on this page have not been checked against primary sources.

Description

Threat

user · unsafe-default · exfiltration

What

Anthropic says a suspected Russian state-nexus operator used Claude-driven workflows across the cyber kill chain, including reconnaissance, phishing infrastructure, credential harvesting, malware evasion, account compromise and data exfiltration. The operation targeted more than 20 organisations.

Detection

Anthropic identified and disrupted the activity. Recorded from Anthropic's September 2026 threat report. Not recreated in a lab.

Fix

Keep agent actions against external networks behind authorization and isolate credentials, mailboxes and customer data from autonomous workflows.

Fix

The operator was the attacker, so the control that protects victims is the model provider's: Anthropic disrupted the operation and strengthened safeguards.

  • Reconfigure anthropic.safeguards to strengthened after the operation was disrupted. Shipped by Anthropic: it disrupted GTG-20006 and strengthened safeguards. Owner: model-provider

References

REPORT

Report a problemJSON