{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0531",
  "aliases": [],
  "published": "2026-09-10T00:00:00Z",
  "firstReported": {
    "date": "2026-09-10",
    "url": "https://www.anthropic.com/threat-intelligence-report-september-2026",
    "publisher": "Anthropic"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "GTG-50020 used Claude-assisted workflows to steal production AI API keys from an evaluation sandbox and attack about 30 AI companies while seeking access to a pre-release Claude model.",
  "details": "## What\n\nAnthropic says a Russian-speaking financially motivated actor caused an AI vendor's automated evaluation sandbox to hand over production AI API keys, then used those keys in attacks against about 30 AI companies over roughly four days. The actor sought a pre-release Claude model but never gained access.\n\n## Detection\n\nAnthropic identified and disrupted the activity. Recorded from Anthropic's September 2026 threat report. Not recreated in a lab.\n\n## Fix\n\nKeep production credentials out of evaluation sandboxes and require authorization before agent workflows access unrelated organizations.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "claude"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://www.anthropic.com/threat-intelligence-report-september-2026"
    },
    {
      "type": "ARTICLE",
      "url": "https://thenextweb.com/news/anthropic-claude-misuse-threat-intelligence-report"
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "behavioural",
      "vulnClasses": [
        "credential-exposure",
        "credential-theft",
        "over-privileged-combination"
      ],
      "cwe": [
        "CWE-522",
        "CWE-693"
      ],
      "noCveReason": "No code defect: the harm arose from an attacker using an agent workflow to misuse credentials exposed by an evaluation sandbox.",
      "cveBoundary": "behavioural",
      "threat": {
        "attacker": "user",
        "vector": "prompt-injection",
        "outcome": "exfiltration"
      },
      "evidence": [
        {
          "kind": "incident",
          "url": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        }
      ],
      "fix": {
        "summary": "The operator was the attacker, so victims rely on Anthropic's disruption and safeguards and on keeping production keys out of evaluation sandboxes.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "anthropic.safeguards",
            "to": "strengthened after the activity was disrupted",
            "why": "Shipped by Anthropic: it disrupted GTG-50020 and strengthened safeguards.",
            "owner": "model-provider"
          },
          {
            "type": "reconfigure",
            "target": "evaluation-sandbox.credentials",
            "to": "no production AI API keys",
            "why": "The targeted organisation's evaluation sandbox handed its production keys to the actor.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "An AI vendor's automated evaluation sandbox using Claude",
          "any": false,
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "model": {
          "value": "Claude; exact model not stated",
          "any": false,
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "goal": {
          "value": "Obtain access to a pre-release Claude model",
          "stated": true,
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "tools": {
          "value": "Automated evaluation sandbox and stolen production AI API keys",
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "approval": {
          "value": "The actor injected instructions into the automated evaluation sandbox",
          "mode": "no-prompt-by-design",
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "inputControl": "operator",
        "agentAction": "The agent workflow uses exposed production keys to attack the vendor and other AI companies.",
        "harm": "credential-theft",
        "divergence": "decomposed-misuse",
        "reach": {
          "value": "Production AI API keys and AI-company systems",
          "kinds": [
            "api-keys",
            "network"
          ],
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "condition": {
          "value": "When malicious instructions reached an automated evaluation sandbox holding production keys",
          "status": "confirmed",
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        },
        "scale": {
          "statement": "About thirty AI companies were attacked in roughly four days",
          "unit": "systems",
          "value": 30,
          "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
        }
      },
      "occurrence": {
        "basis": "real-use",
        "reportedBy": "vendor",
        "responses": [
          {
            "party": "Anthropic",
            "status": "fixed",
            "statement": "Anthropic says it disrupted the activity and strengthened safeguards.",
            "source": "https://www.anthropic.com/threat-intelligence-report-september-2026"
          }
        ]
      },
      "exploitation": {
        "status": "none-known",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://www.anthropic.com/threat-intelligence-report-september-2026",
            "type": "research",
            "note": "Anthropic reported a real operation."
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "claims": [],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "reported-only",
        "missing": [
          "model availability not checked (no registry reference)",
          "trigger not published"
        ]
      },
      "severityBasis": "harm-reach"
    }
  }
}
