← Back to timelineIncident
Attackers steal an AI vendor's credentials
An evaluation sandbox's access controls fail.
Model lab
Incident dateMay–July 2026 (exact dates unknown)
Reported10 Sept 2026
Campaign window; individual breach date unknown.
What happened
Anthropic reports that GTG-50020 redirected an AI vendor's evaluation sandbox with malicious instructions and extracted production API credentials. The attacker then used those keys against the vendor and other targets. Anthropic
Prerelease Claude access attempts failed; Anthropic says its own infrastructure was not compromised. Anthropic reports disrupting the activity. The vendor's recovery is not independently verified here. Anthropic
Sources & attribution
- First-party report 10 Sept 2026Detecting and countering misuse of AI: September 2026
Anthropic. The developer is an interested party. Claims and attributions require their stated qualifications.