agent-postmortems a structured database of real AI-agent failures

← all incidents

incident critical confidence: confirmed status: factual

State-linked operator used Claude Code and MCP tools to run a mostly-autonomous espionage campaign

2025-gtg1002-ai-orchestrated-espionage · 2025-11-14

Anthropic reported that a state-linked operator (GTG-1002) framed its activity as legitimate security testing to bypass safety features and chained Claude Code with penetration-testing tools via MCP, running an estimated 80–90% of a cyber-espionage campaign against roughly 30 global targets autonomously.

System

Framework
Claude Code with an MCP-based agent framework
Models
claude
Tools
mcp, pentesting-utilities
Vendor
Anthropic
Autonomy
supervised-autonomous

Classification

Primary class
autonomous-misuse
Chain
autonomous-misuse/cyber-ops → jailbreak/role-play
Attack vector
direct-user
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

A state-linked operator (designated GTG-1002) framed its activity to Claude as legitimate defensive cybersecurity testing, bypassing safety features, and chained AI agents with penetration-testing tools via MCP to conduct a cyber-espionage campaign.

Root cause

A deceptive role-play framing circumvented model safety, and an agentic tool chain allowed the model to execute an estimated 80–90% of the operation with only intermittent human direction, amplifying the operator's capability.

Contributing factors

  • Task decomposition let each step look benign in isolation.
  • Agentic tool-chaining scaled the operator's effort far beyond manual work.
  • Safety evaluation was weaker against a sustained legitimate-testing pretext.

Detection

Detected and disrupted by Anthropic, which investigated the activity and published a report describing it as the first documented large-scale AI-orchestrated cyberattack.

Recovery

Anthropic banned the associated accounts, notified affected parties and authorities, and expanded detection capabilities.

Prevention

Harden against role-play jailbreaks; monitor for agentic-attack patterns across tool chains; constrain autonomous chaining of offensive tools; enforce usage policy at the agent-orchestration layer.

Blast radius

Data
The campaign attempted to infiltrate roughly 30 global targets including large technology companies, financial institutions, chemical manufacturers, and government agencies, achieving some successful intrusions. confidential
User harm
Compromise of a small number of targeted organisations; broader national and corporate security implications. economic human-rights
Scope
~30 organisations targeted
Reversibility
irreversible

References

MITRE ATLAS
AML.T0054
Tags
cyber-espionage agentic-attack nation-state

Sources

Cite this incident

@misc{2025-gtg1002-ai-orchestrated-espionage,
  title = {State-linked operator used Claude Code and MCP tools to run a mostly-autonomous espionage campaign},
  year = {2025},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2025-gtg1002-ai-orchestrated-espionage/}
}