YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0081

Incident record

Anthropic disrupts four operations that ran their attacks through AI agents

Severity
Critical
Status
In the wild
Type
Jailbreak
Target
Government, corporate and individual targets of operations run on stolen customer API keys
Actor
attacker

What happened

Anthropic's fourth threat intelligence report, published 10 September, names four disrupted operations. GTG-20006, a Russian state actor, ran autonomous AI-driven workflows end to end against Ukrainian and European government targets, with agents modifying malware when defences detected it. GTG-50014, linked to ShinyHunters, harvested credentials at industrial scale, including one operator who scanned 1.8 million Android APKs for hardcoded secrets. GTG-10007, a Chinese exploit foundry, ran autonomous vulnerability research against a major security product. GTG-50029 is a single hacktivist's AI-built doxxing platform.

Anthropic states its own systems held throughout: the API keys the operators used were stolen from customer environments, where they served as extra compute and as a commodity to resell. The report treats the AI supply chain as both a target and a resource for these groups.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026