Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Anthropic says a group it identifies as GTG-1002 used Claude Code as part of an espionage campaign that attempted to infiltrate roughly 30 organizations in 2025. The company assessed with high confidence that the operators were a Chinese state-sponsored group; that attribution is an assessment, not an independently proven fact. Anthropic says Claude handled much of the tactical work, but human operators chose targets and made important strategic decisions.
What did Anthropic say happened?
Anthropic says it detected suspicious activity in mid-September 2025 and investigated an operation targeting organizations in technology, finance, chemical manufacturing and government. The company reported that the campaign attempted to reach roughly 30 organizations and that it validated a small number of successful intrusions. It has not publicly named all affected organizations or provided a precise compromise count.
Anthropic disclosed the campaign on November 13, 2025. The Associated Press also reported on the case, drawing on Anthropic’s account. MITRE ATT&CK catalogs the campaign as C0062.
Who does Anthropic say was responsible?
Anthropic gave the actor the designation GTG-1002 and said it assessed with high confidence that the group was Chinese state-sponsored. MITRE ATT&CK describes C0062 as likely China-nexus. Those descriptions express the sources’ attribution assessments; they do not amount to public proof of the operators’ identity.
How was Claude Code used?
According to Anthropic, operators incorporated Claude Code into a custom attack framework and tried to bypass safeguards by presenting malicious work as legitimate security testing and splitting it into smaller tasks. The company says the system was used across multiple stages of the operation:
- Reconnaissance and identification of potential vulnerabilities
- Testing vulnerabilities and writing exploit code
- Credential harvesting and movement between systems
- Analysis of collected data and attempted exfiltration
This is Anthropic’s account of Claude’s use within an operator-built framework, not evidence that the model independently devised and carried out the campaign from start to finish.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How much of the operation was automated?
Anthropic’s headline-scale figures need to be read narrowly: the 80–90% estimate concerns tactical operations, not every strategic decision or the campaign as a whole. The company says humans remained involved in selecting targets and making consequential choices.
| Reported measure | What it refers to | Attribution and qualification |
|---|---|---|
| Roughly 30 organizations | Attempted targets | Anthropic’s 2025 estimate; not a count of successful intrusions. |
| 80–90% | Share of tactical operations Anthropic says Claude performed | Anthropic’s estimate, not an independent audit; it does not measure the AI’s share of strategic decisions. |
| About four to six | Critical human decision points per campaign | Anthropic’s account; operators still made important decisions. |
| Thousands of requests, often multiple per second | Activity attributed to the campaign’s use of Claude | Anthropic’s corrected wording. On November 14, 2025, the company amended an earlier description that had said “thousands per second.” |
Anthropic characterized the case as “the first documented case of a large-scale cyberattack executed without substantial human intervention.” That is the company’s description, not a universal finding independently established by the public sources. The reported human involvement also matters: “without substantial human intervention” does not mean entirely autonomous.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What is known about victims and evidence?
Anthropic says it confirmed a small number of successful intrusions, but the public reporting does not establish a precise number or identify every affected organization. The sources reviewed also do not establish a validated, campaign-specific public indicator set. MITRE’s C0062 entry records the campaign and summarizes sectors and reported techniques; it should not be treated as a public victim list.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What did Anthropic do, and what should security teams take from the report?
Anthropic says it banned accounts as they were identified, notified affected organizations as appropriate and coordinated with authorities during an investigation lasting about ten days. These response details are the company’s account.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
The report illustrates a risk for security teams: AI integrated into an attack framework can accelerate work across multiple stages, while people retain control of targets and pivotal decisions. It does not show that every AI system can reproduce this operation or that a particular defensive product would stop it.
Anthropic recommends exploring AI for security operations center (SOC) automation, threat detection, vulnerability assessment and incident response, alongside continued investment in safeguards. For teams assessing their own exposure, practical questions include:
Quick Recap
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Can analysts see which AI tools and accounts are being used, and review their activity?
- Are access rights limited to the systems and data needed for each task?
- Do sensitive actions require human approval, with clear escalation paths?
- Can investigators retain evidence and reconstruct what an AI-enabled workflow did?
- Have defensive AI capabilities been assessed against the team’s actual workflows rather than assumed to prevent an attack?
CISA provides broader guidance on PRC state-sponsored cyber threats and incident reporting, but that general material is not campaign-specific evidence about GTG-1002.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

