Anthropic Disrupts Espionage Operation That Used Claude in Cyberattacks

Anthropic says it blocked accounts linked to the GTG-20006 group, which allegedly used Claude to automate parts of espionage attacks against targets in Ukraine and Europe.

Anthropic described GTG-20006 as a disrupted Russian-speaking espionage activity whose operators, according to the company, used the Claude model to automate parts of cyberattacks. The company said this in a report published on September 10, 2026. This was not a vulnerability in Claude or a compromise of Anthropic’s systems; the company says it blocked the actors’ accounts and incorporated its findings into its protective measures.

According to Anthropic, the group deployed AI-driven workflows to develop tools, procure infrastructure, conduct phishing, manage compromised systems and exfiltrate data. Human operators reportedly continued to select targets and review results, while the model performed repetitive technical tasks.

Anthropic Identified GTG-20006 After Detecting Account Abuse

Anthropic identified more than 20 target organizations. They included government ministries, defense and intelligence agencies, embassies, think tanks and defense-industry companies. The targets were located mainly in Ukraine and Europe, the report says.

The company describes the use of phishing, credential theft and the exploitation of hotel Wi-Fi providers. AI also reportedly helped manage systems that attackers had already compromised and exfiltrate data from them.

One significant finding concerns the malware process. According to Anthropic, automated agents monitored whether security products detected malicious code. After detection, they reportedly modified and rebuilt the malware to avoid further detection.

Automation of Known Techniques, Not a New Claude Vulnerability

The activity described does not represent confirmation of a new security flaw that Claude users would need to fix with an update. According to the available information, it involved abusing the model to support methods long known in espionage campaigns: social engineering, attack-infrastructure development, access management and malicious-code modification.

The significance of the case lies in the level of automation. If AI takes over repetitive tasks, it can reduce the time needed to run multiple parts of a campaign simultaneously. Anthropic also says, however, that people remained responsible for target selection and reviewing outputs.

Link to Midnight Blizzard Not Independently Confirmed So Far

Anthropic links the GTG-20006 operators to publicly available findings about the Midnight Blizzard group. Reuters reported that U.S. authorities have already attributed Midnight Blizzard to Russia’s foreign intelligence service, the SVR.

However, no direct and independent public confirmation has been published that GTG-20006 is the same group or belongs to a specific Russian state service. The affected organizations have likewise not been named, and the full extent of the reported intrusions, compromises or stolen data has not been publicly confirmed. It is also unknown whether Russian authorities or the alleged operators have responded to the findings.

What Potential Targets Should Monitor

For organizations linked to Ukraine, defense or diplomacy, the practical context is primarily phishing and credential abuse. Relevant steps include assessing user resilience against phishing, reviewing email and remote-access protections, checking DNS records and monitoring unusual activity.

Another important question is whether Anthropic, Microsoft or other defenders will publish specific indicators of compromise and more precise technical recommendations. Potential independent confirmation of the GTG-20006 attribution should also be monitored, along with further documented cases of automated detection evasion through agentic AI workflows.

Sources

Verified and updated: 09/11/2026 15:25

Sharing