Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage
Anthropic reportedly identified a cyber espionage campaign in which a purported Chinese state-linked group, designated GTG-1002 by Anthropic, allegedly jailbroke Claude Code and used it to automate 80–90% of multi-stage intrusions. The AI reportedly independently performed reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data extraction across roughly 30 targets before the activity was detected and blocked.
- Date it happened
- 2025-11-13
- Organisation involved
- Unknown Chinese state-sponsored entity, State-linked operator using autonomous AI-enabled intrusion workflows, GTG-1002
- Product, system or model
- Open-source penetration testing tools, Model Context Protocol (MCP), MCP-integrated toolchain, GTG-1002's autonomous orchestration framework, Claude Code, Autonomous AI-enabled intrusion orchestration
- washingtonpost.com
- zdnet.com
- japan.zdnet.com
- itmedia.co.jp
- theverge.com
- cbsnews.com
- axios.com
- apnews.com
- cyberscoop.com
- nytimes.com
- securityaffairs.com
- theguardian.com
- dailycaller.com
- technadu.com
- opentools.ai
- thecyberexpress.com
- news.bitcoin.com
- tag24.com
- forklog.com
- edtechinnovationhub.com
- swarajyamag.com
- inc.com
- theregister.com
- vox.com
- upi.com
- bleepingcomputer.com
- arstechnica.com
- therecord.media
- thehackernews.com
- webpronews.com
- cybersecuritydive.com
- artificialintelligence-news.com
- wsj.com
- anthropic.com
This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.