{ "actor": "Russian-speaking, financially motivated actor (tracked by Anthropic as GTG-50020)", "actor_type": "cybercriminal", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "significant", "autonomy_level": "fully-autonomous", "autonomy_pct": null, "category": "infrastructure-abuse-supply-chain", "confidence": "primary", "date_disclosed": "2026-09-10", "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "gtg-50020-ai-vendor-api-key-theft", "impact": "Per Anthropic: roughly 26 gigabytes of data exfiltrated from one victim; production AI API keys stolen from AI vendors' customer environments and reused for the actor's own workloads; extortion or dark-web sale sought at US$1.5 to 2.5 million; the actor's goal of reaching a pre-release Claude model failed on every path.", "last_updated": "2026-10-10", "lifecycle_phases": [ "recon", "initial-access", "execution", "credential-access", "exfiltration", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Anthropic states the actor never compromised Anthropic's own systems; the stolen keys were customers' keys taken from customers' environments. The report publishes egress indicators for the cluster." ], "model_families": [ "claude" ], "models": [], "name": "GTG-50020 autonomous exploitation pipeline against ~30 AI companies and theft of production API keys", "related": [ "gtg-2002-vibe-hacking-extortion", "gtg-5004-ai-ransomware-raas", "gtg-20006-agentic-espionage", "gtg-50014-agentic-mass-exfiltration", "gtg-10007-agent-swarm-intrusions", "gtg-50029-hacktivist-agentic-recon" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20261009173227/https://www.anthropic.com/threat-intelligence-report-september-2026", "date": "2026-09-10", "publisher": "Anthropic", "title": "Countering misuse of AI: September 2026", "type": "first-party-disclosure", "url": "https://www.anthropic.com/threat-intelligence-report-september-2026" } ], "status": "confirmed", "summary": "In its September 2026 report \"Countering misuse of AI\", Anthropic disclosed a cluster it tracks as GTG-50020, \"a Russian-speaking, financially-motivated actor\" with a history of intrusions against hotel booking and financial technology platforms. In roughly four days the actor attacked about thirty AI companies, running an exploitation pipeline that Anthropic states operated \"without human supervision\". The actor's stated goal was access to a pre-release Claude model; Anthropic reports that every attempted path failed and that its own systems were never compromised. Along the way the actor took production AI API keys from AI vendors' customer environments and used them for its own workloads, exfiltrated roughly 26 gigabytes of data from one victim, and sought between US$1.5 and 2.5 million through extortion or sale on dark-web forums. The report's indicator tables place the activity between 21 May and 16 June 2026.", "targets": { "countries": [], "orgs_affected": 30, "records_exfiltrated": null, "sectors": [ "technology" ] } }