{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0530",
  "aliases": [],
  "published": "2026-09-10T00:00:00Z",
  "firstReported": {
    "date": "2026-09-10",
    "url": "https://www.anthropic.com/threat-intelligence-report-september-2026",
    "publisher": "Anthropic"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "GTG-50014 used Claude-powered multi-agent workflows to scan and take over target systems, steal data and reuse stolen AI API keys in follow-on attacks.",
  "details": "## What\n\nAnthropic says ShinyHunters-affiliated actors used Claude to accelerate opportunistic scanning, exploitation and takeover activity. After obtaining AI API keys during an intrusion, the actors switched their workloads to the victims' keys and continued attacks.\n\n## Detection\n\nAnthropic identified and disrupted the activity. Recorded from Anthropic's September 2026 threat report. Not recreated in a lab.\n\n## Fix\n\nTreat AI API keys as production credentials, rotate them after compromise, and keep multi-agent workflows from operating on unrelated targets.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "claude"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://www.anthropic.com/threat-intelligence-report-september-2026"
    },
    {
      "type": "ARTICLE",
      "url": "https://thenextweb.com/news/anthropic-claude-misuse-threat-intelligence-report"
    }
  ],
  "database_specific": {
    "severity": "CRITICAL",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "behavioural",
      "vulnClasses": [
        "credential-theft",
        "over-privileged-combination"
      ],
      "cwe": [
        "CWE-522",
        "CWE-693"
      ],
      "taxonomy": {
        "atlas": [
          "AML.T0124",
          "AML.T0049",
          "AML.T0012"
        ]
      },
      "noCveReason": "No code defect: the harm arose from an attacker using Claude to automate opportunistic intrusions.",
      "cveBoundary": "behavioural",
      "threat": {
        "attacker": "user",
        "vector": "unsafe-default",
        "outcome": "exfiltration"
      },
      "evidence": [
        {
          "kind": "incident",
          "url": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        }
      ],
      "fix": {
        "summary": "The operator was the attacker, so victims rely on Anthropic's disruption and safeguards and on rotating AI API keys after an intrusion.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "anthropic.safeguards",
            "to": "strengthened after the activity was disrupted",
            "why": "Shipped by Anthropic: it disrupted GTG-50014 and strengthened safeguards.",
            "owner": "model-provider"
          },
          {
            "type": "reconfigure",
            "target": "ai-api-keys",
            "to": "rotated after any intrusion",
            "why": "The targeted organisation's stolen AI API keys ran the attackers' follow-on workloads.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "Multi-agent workflows using Claude",
          "any": false,
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "model": {
          "value": "Claude Haiku, Sonnet or Opus; exact model not stated",
          "any": false,
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "goal": {
          "value": "Scan, exploit and take over target systems and reuse stolen AI API keys",
          "stated": true,
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "tools": {
          "value": "Multi-agent reconnaissance, exploitation and bulk-export tooling",
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "approval": {
          "value": "The report describes multi-agent campaigns operating with minimal human input",
          "mode": "auto-approve",
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "inputControl": "operator",
        "agentAction": "The agent workflow scans and takes over target systems and reuses stolen AI API keys.",
        "harm": "credential-theft",
        "divergence": "decomposed-misuse",
        "reach": {
          "value": "Internet-facing systems, SaaS tenants and AI API accounts",
          "kinds": [
            "network",
            "api-keys",
            "cloud-credentials"
          ],
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "condition": {
          "value": "When stolen AI API keys were fed back into multi-agent attack workflows",
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        }
      },
      "occurrence": {
        "basis": "real-use",
        "reportedBy": "vendor",
        "responses": [
          {
            "party": "Anthropic",
            "status": "fixed",
            "statement": "Anthropic says it disrupted the activity and strengthened safeguards.",
            "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
          }
        ]
      },
      "exploitation": {
        "status": "none-known",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://www.anthropic.com/threat-intelligence-report-september-2026",
            "type": "research",
            "note": "Anthropic reported a real operation."
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "claims": [],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "reported-only",
        "missing": [
          "model availability not checked (no registry reference)",
          "trigger not published"
        ]
      },
      "severityBasis": "harm-reach"
    }
  }
}
