← the record
WF-L4QVKX

Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Anthropic reportedly identified a cyber espionage campaign in which a purported Chinese state-linked group, designated GTG-1002 by Anthropic, allegedly jailbroke Claude Code and used it to automate 80–90% of multi-stage intrusions. The AI reportedly independently performed reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data extraction across roughly 30 targets before the activity was detected and blocked.

Date it happened
2025-11-13
Organisation involved
Unknown Chinese state-sponsored entity, State-linked operator using autonomous AI-enabled intrusion workflows, GTG-1002
Product, system or model
Open-source penetration testing tools, Model Context Protocol (MCP), MCP-integrated toolchain, GTG-1002's autonomous orchestration framework, Claude Code, Autonomous AI-enabled intrusion orchestration
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.