Case · DiggingBeagle record

GTG-50029 used agentic workflows across a European hacktivist campaign

Anthropic reports that a single French-speaking actor used Claude and sub-agent workflows against European political, media, think-tank and SaaS targets, gaining internal access to at least 14 of 42 tracked entities.

Anthropic's GTG-50029 case study covering spring and early-summer 2026 activity. Victim identities are largely withheld in the public report.

First seen
Feb 6, 2026
Case kind
incident
AI role
WITH AI
Claims
5

Reconstruction

GTG-50029 compresses several capabilities that usually belong to a larger team. Anthropic reports that one actor built a Rust scanner for exposed API keys, rotated stolen keys through a proxy layer, and used an agentic framework whose sub-agents handled reconnaissance, code review and validation of findings from multiple models.

The campaign combined familiar web compromise with custom exploit development. Anthropic says the actor used Claude to develop and debug a previously undocumented WordPress re-installation race condition that created rogue administrator accounts, succeeding against at least four victim sites. In another target, agents iterated over an exposed search endpoint and exfiltrated about 140,000 records containing political opinions.

Across 42 tracked targets, Anthropic says the actor obtained internal access to at least 14. The report also describes webshells, credential-harvesting plugins, poisoned backups and a doxxing platform built by the same operator. The important shift is operational scale, not that every underlying technique was new.

Mechanism & boundary

  1. 01

    Scan for exposed API keys

    A custom Rust scanner identifies and validates keys in public containers and other exposed material.

    Boundary: public exposure / stolen credentials

  2. 02

    Rotate stolen keys through local proxy

    The actor blends model traffic with legitimate owners' usage.

    Boundary: stolen credential / AI provider

  3. 03

    Delegate reconnaissance and exploitation to sub-agents

    Agent workflows perform pre-auth and post-auth recon, code review and finding validation.

    Boundary: operator / multi-agent harness

  4. 04

    Develop target-specific exploit paths

    Claude-assisted sessions produce and debug exploits such as the WordPress re-installation race condition.

    Boundary: agent workflow / target application

  5. 05

    Persist and exfiltrate

    Webshells, credential-harvesting plugins, poisoned backups and data-processing tooling support continued access and theft.

    Boundary: victim environment / actor infrastructure

Timeline

  1. Feb 6, 2026

    Earliest listed key-validation infrastructure appears

    report

    Anthropic's GTG-50029 indicator table begins on February 6.

  2. Mar 25, 2026

    Primary attack-exit window begins

    report

    Anthropic lists a set of VPN and datacenter exits beginning March 25.

  3. May 13, 2026

    Browser-C2 infrastructure appears

    report

    Anthropic lists the campaign's browser-C2 hostname from May 13.

  4. Sep 10, 2026

    Anthropic publishes GTG-50029 case study

    response

    The report summarizes the campaign, target counts and data theft.

Claims & evidence

reported findingsupported

Anthropic reports that one compromised political campaign platform yielded about 140,000 records that included users' political opinions.

Measured value
140000 records exfiltrated from one platform
Method
Anthropic threat-intelligence investigation
Period
spring 2026
reported findingsupported

Anthropic estimates that the actor exfiltrated 12 to 26 GB of database dumps across affected targets and also obtained a 15,000-message mailbox.

Scope: Anthropic's aggregate estimate across tracked target activity.

reported findingsupported

Across 42 tracked target entities, Anthropic reports internal access to at least 14.

Measured value
14 tracked target entities with internal access
Method
Anthropic threat-intelligence investigation
Period
spring to early summer 2026
reported findingsupported

Anthropic reports that a single French-speaking actor used Claude and sub-agent workflows against European political parties, media, think tanks and SaaS providers.

reported findingsupported

Anthropic reports that the actor used Claude to develop and debug a previously undocumented WordPress re-installation race condition that created rogue administrator accounts and succeeded against at least four victim websites.

  • supports
    Countering misuse of AI: September 2026

    Locator: GTG-50029, novel exploitation

    The report attributes development and debugging of the race-condition exploit to the actor's Claude-assisted workflow.

Evidence visuals

chart

GTG-50029 tracked targets and internal access

Anthropic GTG-50029 threat-intelligence investigation.

Measuretarget entities
Tracked targets42
Internal access14
Internal access is reported as at least 14, so the second bar is a lower bound. · Source: GTG-50029 used agentic workflows across a European hacktivist campaign

diagram

GTG-50029 single-operator agentic workflow

  1. Exposed API keys

    Scanner finds and validates public keys

  2. Local proxy layer

    Rotates stolen key usage

  3. AI sub-agents

    Recon, code review and finding validation

  4. Target-specific exploit

    Includes WordPress race-condition development

  5. Persistence

    Webshells, credential plugins and poisoned backups

  6. Data processing

    Staging, search and exfiltration

  • Exposed API keys Local proxy layer: credential rotation
  • Local proxy layer AI sub-agents: model access
  • AI sub-agents Target-specific exploit: develop and validate
  • Target-specific exploit Persistence: compromise
  • Persistence Data processing: collection
Project-authored reconstruction of Anthropic's GTG-50029 case study. · Source: GTG-50029 used agentic workflows across a European hacktivist campaign

Implications

Agentic tooling can give a single operator enough throughput to manage discovery, exploit development, persistence and stolen-data processing across many targets. Defenders should watch for the orchestration layer, repeated key-validation infrastructure and machine-paced adaptation across otherwise unrelated victims.

Controls & mitigations

  • Continuously scan public repositories, images and containers for exposed AI API keys.
  • Detect model access that rotates across unrelated customer keys or proxy infrastructure.
  • Harden WordPress recovery and re-installation paths and monitor unexpected administrator creation.
  • Treat backup integrity as part of persistence detection.
  • Correlate rapid multi-target reconnaissance and exploitation across cloud and SaaS telemetry.

What remains unknown

  • Victim identities are largely withheld in the public report.
  • Anthropic's 12 to 26 GB figure is an estimate rather than a byte-exact total.
  • The report does not provide a complete accounting of which actions were autonomous versus directly operator-driven.

Cite this record

DiggingBeagle. “GTG-50029 used agentic workflows across a European hacktivist campaign.” First seen Feb 6, 2026. https://diggingbeagle.com/cases/gtg-50029-used-agentic-workflows-across-a-european-hacktivist-campaign/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.