Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-12 ยท updated: 2026-09-12 ยท tags: [incident, global, espionage] ยท confidence: high ยท severity: critical ยท affected_sectors: [global] ยท au_impact: true

Anthropic has published a threat-intelligence report covering December 2025 to August 2026, disclosing that it detected and disrupted a Russian state-sponsored espionage cluster it tracks as GTG-20006 โ€” aligned with Midnight Blizzard (also known as APT29, Cozy Bear and BlueBravo, attributed by Western agencies to Russia's SVR) โ€” which used Claude to develop an AI-assisted workflow that automatically rebuilt and re-deployed its toolkit when security products detected it, undermining static detections by regenerating artefacts faster than signature-based blocking could adapt. The actor compromised hotel Wi-Fi providers and changed DNS records to redirect travellers to attacker-controlled infrastructure, activity Anthropic links to Microsoft's investigation of Storm-2945, a sub-cluster of Midnight Blizzard. Targets included members of the Ukrainian government, military and diplomatic staff and entities in the drone supply chain; after gaining access to mailboxes at two drone-component manufacturers the group targeted a military drone maker and stole a complete proprietary software development kit for a drone vision system, with more than 20 government, intelligence, diplomatic and defence organisations targeted overall. The same report documents industrial-scale illicit distillation of Claude by seven China-based labs โ€” including Alibaba, Moonshot, DeepSeek, Z.ai (Zhipu) and MiniMax โ€” using networks of fake accounts created with stolen credit cards, credentials and API keys, and introduces Anthropic's "Generative Threat Group" taxonomy spanning state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions and politically motivated individuals. Anthropic's framing is the analytical headline: AI has "collapsed the labour and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators", with multi-agent frameworks executing reconnaissance, exploitation and exfiltration rather than simple chatbot exchanges. Unlike comparable vendor disclosures the report includes in-depth campaign analysis and indicators of compromise, though it omits any figure for the scale of misuse detected overall.

Attribute Detail
Sector Global (Macro)
Date 2026-09-12
Source Anthropic
Reliability Tier 1