ACVE-2026-0530
GTG-50014 used Claude-powered multi-agent workflows to scan and take over target systems, steal data and reuse stolen AI API keys in follow-on attacks.
Exposure
Reproducibility: partial (model availability not checked (no registry reference); trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
Description
Threat
user · unsafe-default · exfiltration
What
Anthropic says ShinyHunters-affiliated actors used Claude to accelerate opportunistic scanning, exploitation and takeover activity. After obtaining AI API keys during an intrusion, the actors switched their workloads to the victims' keys and continued attacks.
Detection
Anthropic identified and disrupted the activity. Recorded from Anthropic's September 2026 threat report. Not recreated in a lab.
Fix
Treat AI API keys as production credentials, rotate them after compromise, and keep multi-agent workflows from operating on unrelated targets.
Fix
The operator was the attacker, so victims rely on Anthropic's disruption and safeguards and on rotating AI API keys after an intrusion.
- Reconfigure
anthropic.safeguardstostrengthened after the activity was disrupted. Shipped by Anthropic: it disrupted GTG-50014 and strengthened safeguards. Owner: model-provider - Reconfigure
ai-api-keystorotated after any intrusion. The targeted organisation's stolen AI API keys ran the attackers' follow-on workloads. Owner: operator