ModelRiskIndex

Incident database / 2025-11-13

State-sponsored actor used Claude Code to automate intrusion campaign

Agentic misuse / social-engineering the model's safety contextClaude Sonnet 4.5

Anthropic disclosed a campaign in which a state-sponsored group manipulated Claude Code into automating reconnaissance and exploitation against ~30 targets by role-playing as a legitimate security firm — an early, well-documented case of agentic-scale misuse of a frontier coding agent.

Outcome. Accounts banned, targets notified, public disclosure with TTPs. Cited here as evidence that agentic deployment risk is a property of the deployment pattern, not only the model.

Sources
Sources (1)
  • Anthropic disclosure
    Anthropic provider artifacts · provider artifact · source tier B · anthropic.com · retrieved 2026-08-03
How to cite thisCC BY 4.0 — reuse freely, attribution required

Plain

ModelRiskIndex. "State-sponsored actor used Claude Code to automate intrusion campaign." Incident database, 2025-11-13. https://modelriskindex.com/incidents/claude-code-espionage-campaign-2025
BibTeX
@misc{mri-2025-11-13,
  title  = {State-sponsored actor used Claude Code to automate intrusion campaign},
  author = {{ModelRiskIndex}},
  year   = {2025},
  note   = {Incident database, 2025-11-13},
  url    = {https://modelriskindex.com/incidents/claude-code-espionage-campaign-2025}
}

Please cite the dated entry rather than the site root. Every assessment here is a point-in-time judgment bound to evidence retrieved on a specific date — an undated citation asserts something the data does not.

All incidents