Skip to main content

GTG-1002 used a coding agent under human direction to run an espionage campaign

Anthropic reported on 13 November 2025 that a group it designates GTG-1002, assessed as Chinese state sponsored, wrapped Claude Code in its own framework and directed it against about 30 targets, with the model performing most tactical work. Humans chose targets, built the framework and reviewed results. A person directed every campaign, so this is misuse, recorded to show what the ledger excludes.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
ESC-2026-0007
Kind
Adjacent, not an escape
Jurisdiction
Global
Last verified
Added
  • Anthropic states the operators broke the campaign into small tasks and told the model it worked for a legitimate cybersecurity firm doing defensive testing.
  • Anthropic states about 30 targets were attempted and a small number of intrusions succeeded.
  • Anthropic states the model performed 80 to 90 percent of the campaign with four to six critical human decision points per campaign.
  • Anthropic states it detected the activity in mid September 2025, investigated over ten days, banned accounts, notified affected entities and coordinated with authorities.

Dimension by dimension

2 dimensions, each one stated, silent or open

Classifiers and refusals, Disclosure. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

Classifiers and refusalsSilent
The operators evaded refusals by decomposing tasks and asserting a defensive pretext, which is a jailbreak by humans and outside this ledger's rule.Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaign, primary source, 13 November 2025.
DisclosureStated
The vendor published its own threat report naming the actor designation and its response.Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaign, primary source, 13 November 2025.

Figures

Every number, with who measured it and when

  1. 30 targets

    targets attempted, printed as approximately

    Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .

  2. 4 decision points

    critical human decision points per campaign, lower bound as printed

    Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .

  3. 6 decision points

    critical human decision points per campaign, upper bound as printed

    Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .

  4. 10 days

    investigation length

    Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .

What it changes

For a team that runs agents

Excluded because a human held the objective throughout; the agent did what it was asked. For a team the useful line is the one Anthropic draws itself: a defensive pretext plus task decomposition gets past per request refusals, so abuse detection has to read the campaign, not the prompt. That is the same trajectory level reading the evaluation incidents in this record call for.

Sources

What this record was verified against

  1. Anthropic, Disrupting the first reported AI orchestrated cyber espionage campaignPrimary · 13 November 2025

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID ESC-2026-0007 is permanent and is never reused.

In a sentence
According to the GAGE Escape Record (as of 16 September 2026), gtg-1002 used a coding agent under human direction to run an espionage campaign.
APA
GAGE (Global Academy of Generative-AI Education). (2026). GTG-1002 used a coding agent under human direction to run an espionage campaign. Escape Record. Retrieved 16 September 2026, from https://www.gage.academy/tools/escape-record/records/ESC-2026-0007-gtg-1002-human-directed-espionage-using-a-coding-agent
MLA
"GTG-1002 used a coding agent under human direction to run an espionage campaign." Escape Record, GAGE (Global Academy of Generative-AI Education), 16 September 2026, https://www.gage.academy/tools/escape-record/records/ESC-2026-0007-gtg-1002-human-directed-espionage-using-a-coding-agent.
Chicago
GAGE (Global Academy of Generative-AI Education). "GTG-1002 used a coding agent under human direction to run an espionage campaign." Escape Record. Last modified 16 September 2026. https://www.gage.academy/tools/escape-record/records/ESC-2026-0007-gtg-1002-human-directed-espionage-using-a-coding-agent.
Permalink
https://www.gage.academy/tools/escape-record/records/ESC-2026-0007-gtg-1002-human-directed-espionage-using-a-coding-agent

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any lab disclosure, institute report or wire story.

Back to the full ledger, or every record for Global and every adjacent, not an escape record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.