← Back to timelineAI THREAT TRACKER / AI-012 · Incident
Attackers steal an AI vendor's credentials
An evaluation sandbox's access controls fail.
Model lab
Topics
OCCURREDMay–July 2026 (exact dates unknown)
PUBLIC ACCOUNT10 Sept 2026
EVIDENCEFirst-party account
About these dates
Campaign window; individual breach date unknown.
What happened
Anthropic reports that GTG-50020 redirected an AI vendor's evaluation sandbox with malicious instructions and extracted production API credentials. The attacker then used those keys against the vendor and other targets. Anthropic ↗
Prerelease Claude access attempts failed; Anthropic says its own infrastructure was not compromised. Anthropic reports disrupting the activity. The vendor's recovery is not independently verified here. Anthropic ↗
Sources & attribution
- First-party report 10 Sept 2026Detecting and countering misuse of AI: September 2026 ↗
Anthropic. The developer is an interested party. Claims and attributions require their stated qualifications.