GTG-1002 used a coding agent under human direction to run an espionage campaign
Anthropic reported on 13 November 2025 that a group it designates GTG-1002, assessed as Chinese state sponsored, wrapped Claude Code in its own framework and directed it against about 30 targets, with the model performing most tactical work. Humans chose targets, built the framework and reviewed results. A person directed every campaign, so this is misuse, recorded to show what the ledger excludes.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- ESC-2026-0007
- Kind
- Adjacent, not an escape
- Jurisdiction
- Global
- Last verified
- Added
- Anthropic states the operators broke the campaign into small tasks and told the model it worked for a legitimate cybersecurity firm doing defensive testing.
- Anthropic states about 30 targets were attempted and a small number of intrusions succeeded.
- Anthropic states the model performed 80 to 90 percent of the campaign with four to six critical human decision points per campaign.
- Anthropic states it detected the activity in mid September 2025, investigated over ten days, banned accounts, notified affected entities and coordinated with authorities.
Dimension by dimension
2 dimensions, each one stated, silent or open
Classifiers and refusals, Disclosure. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- Classifiers and refusalsSilent
- The operators evaded refusals by decomposing tasks and asserting a defensive pretext, which is a jailbreak by humans and outside this ledger's rule.Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaign, primary source, 13 November 2025.
- DisclosureStated
- The vendor published its own threat report naming the actor designation and its response.Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaign, primary source, 13 November 2025.
Figures
Every number, with who measured it and when
- 30 targets
targets attempted, printed as approximately
Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .
- 4 decision points
critical human decision points per campaign, lower bound as printed
Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .
- 6 decision points
critical human decision points per campaign, upper bound as printed
Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .
- 10 days
investigation length
Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .
What it changes
For a team that runs agents
Excluded because a human held the objective throughout; the agent did what it was asked. For a team the useful line is the one Anthropic draws itself: a defensive pretext plus task decomposition gets past per request refusals, so abuse detection has to read the campaign, not the prompt. That is the same trajectory level reading the evaluation incidents in this record call for.
Sources
What this record was verified against
- Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaignPrimary · 13 November 2025
Related
Records that sit beside this one
Four evaluation runs at Anthropic and Meta reached real companies through a misconfigured third party environment
United States · verified 16 September 2026
Anthropic states that due to a misunderstanding with its evaluation partner internet access was available when the evaluation assumed it was not, and names Irregular as that partner.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID ESC-2026-0007 is permanent and is never reused.
- In a sentence
- According to the GAGE Escape Record (as of 16 September 2026), gtg-1002 used a coding agent under human direction to run an espionage campaign.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). GTG-1002 used a coding agent under human direction to run an espionage campaign. Escape Record. Retrieved 16 September 2026, from https://www.gage.academy/tools/escape-record/records/ESC-2026-0007-gtg-1002-human-directed-espionage-using-a-coding-agent
- MLA
- "GTG-1002 used a coding agent under human direction to run an espionage campaign." Escape Record, GAGE (Global Academy of Generative-AI Education), 16 September 2026, https://www.gage.academy/tools/escape-record/records/ESC-2026-0007-gtg-1002-human-directed-espionage-using-a-coding-agent.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "GTG-1002 used a coding agent under human direction to run an espionage campaign." Escape Record. Last modified 16 September 2026. https://www.gage.academy/tools/escape-record/records/ESC-2026-0007-gtg-1002-human-directed-espionage-using-a-coding-agent.
- Permalink
- https://www.gage.academy/tools/escape-record/records/ESC-2026-0007-gtg-1002-human-directed-espionage-using-a-coding-agent
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any lab disclosure, institute report or wire story.
Back to the full ledger, or every record for Global and every adjacent, not an escape record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.