Incident database / 2025-11-13
State-sponsored actor used Claude Code to automate intrusion campaign
Anthropic disclosed a campaign in which a state-sponsored group manipulated Claude Code into automating reconnaissance and exploitation against ~30 targets by role-playing as a legitimate security firm — an early, well-documented case of agentic-scale misuse of a frontier coding agent.
Outcome. Accounts banned, targets notified, public disclosure with TTPs. Cited here as evidence that agentic deployment risk is a property of the deployment pattern, not only the model.
Sources
Sources (1)
How to cite thisCC BY 4.0 — reuse freely, attribution required
Plain
ModelRiskIndex. "State-sponsored actor used Claude Code to automate intrusion campaign." Incident database, 2025-11-13. https://modelriskindex.com/incidents/claude-code-espionage-campaign-2025
BibTeX
@misc{mri-2025-11-13,
title = {State-sponsored actor used Claude Code to automate intrusion campaign},
author = {{ModelRiskIndex}},
year = {2025},
note = {Incident database, 2025-11-13},
url = {https://modelriskindex.com/incidents/claude-code-espionage-campaign-2025}
}Please cite the dated entry rather than the site root. Every assessment here is a point-in-time judgment bound to evidence retrieved on a specific date — an undated citation asserts something the data does not.