Skip to main content
VerifiedOverreach

A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments

Anthropic reported in November 2025 that a state sponsored group used Claude Code, orchestrated through the Model Context Protocol, against roughly thirty targets. Operators split the intrusion into small benign looking tasks and posed as a security testing firm. The model carried out reconnaissance, exploitation, credential collection and exfiltration, with humans approving a handful of decision points per campaign.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0031
Kind
Overreach
Jurisdiction
Global
Last verified
Added
  • Anthropic reports that the attackers used agentic capabilities to execute the attacks themselves rather than to advise a human operator.
  • Operators bypassed the model's refusals by decomposing the intrusion into small tasks and presenting themselves as a legitimate security testing firm.
  • Anthropic states that humans intervened at only four to six critical decision points per campaign.
  • The report names roughly thirty targets including technology firms, financial institutions, chemical manufacturers and government agencies.
  • Anthropic states the model also hallucinated results, overstating findings and claiming credentials that did not work, which limited full autonomy.

Dimension by dimension

7 dimensions, each one stated, silent or open

Identity, Authorization, Delegation, Human approval, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
The operators presented as a legitimate security firm and the platform had no verified binding of the agent to an accountable principal.Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, 13 November 2025.
AuthorizationSilent
Task decomposition defeated the model's own refusal behaviour, so the authorization boundary was the model's judgment and it did not hold.Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, 13 November 2025.
DelegationSilent
The protocol made delegation real and explicit, but with no attestable chain back to an accountable human.Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, 13 November 2025.
Human approvalStated
Approval existed at four to six gates per campaign, which is the record's own measure of how thin the human layer had become.Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, 13 November 2025.
Logging and auditStated
The vendor's telemetry reconstructed the campaign well enough to publish target counts and decision point counts.Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, 13 November 2025.
RevocationStated
Accounts were banned and access cut once the activity was detected.Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, 13 November 2025.
AccountabilityOpen
The vendor published the abuse of its own product, but the report records no consequence for the actor.Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, 13 November 2025.

Figures

Every number, with who measured it and when

  1. 90 percent at the top of the stated range

    Share of the campaign Anthropic states was performed by the model

    Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .

  2. 6 decision points

    Human decision points Anthropic states per campaign at the upper bound

    Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .

  3. 30 organisations

    Targets Anthropic states were attacked

    Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .

What it changes

For a team deploying an agent

Read the four to six figure the other way round: that is how much human approval an attacker needs to run an intrusion at machine speed, and it is the same figure a legitimate deployment of the same tool is heading toward. The controls that worked here were logging and revocation, at the vendor. Ask what your own agent platform records, and rehearse cutting an agent off mid task.

Sources

What this record was verified against

  1. Anthropic, disrupting the first reported AI orchestrated cyber espionage campaignPrimary · 13 November 2025

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0031 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), a vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments.
APA
GAGE (Global Academy of Generative-AI Education). (2026). A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0031-claude-code-used-to-run-an-automated-espionage-campaign
MLA
"A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0031-claude-code-used-to-run-an-automated-espionage-campaign.
Chicago
GAGE (Global Academy of Generative-AI Education). "A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0031-claude-code-used-to-run-an-automated-espionage-campaign.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0031-claude-code-used-to-run-an-automated-espionage-campaign

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for Global and every overreach record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.