Tools AI Risk Radar ai-incident-0081
Incident record
Anthropic disrupts four operations that ran their attacks through AI agents
- Severity
- Critical
- Status
- In the wild
- Type
- Jailbreak
- Target
- Government, corporate and individual targets of operations run on stolen customer API keys
- Actor
- attacker
What happened
Anthropic's fourth threat intelligence report, published 10 September, names four disrupted operations. GTG-20006, a Russian state actor, ran autonomous AI-driven workflows end to end against Ukrainian and European government targets, with agents modifying malware when defences detected it. GTG-50014, linked to ShinyHunters, harvested credentials at industrial scale, including one operator who scanned 1.8 million Android APKs for hardcoded secrets. GTG-10007, a Chinese exploit foundry, ran autonomous vulnerability research against a major security product. GTG-50029 is a single hacktivist's AI-built doxxing platform.
Anthropic states its own systems held throughout: the API keys the operators used were stolen from customer environments, where they served as extra compute and as a commodity to resell. The report treats the AI supply chain as both a target and a resource for these groups.
Sources
- Anthropic: threat intelligence report, September 2026www.anthropic.com/threat-intelligence-report-september-2026
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026