By NHI Mgmt Group Editorial TeamBased on Astrix Security: “The first reported AI-orchestrated cyber espionage campaign: Deconstructing the Anthropic Report” (November 17, 2025)

TL;DR: Anthropic disrupted the first reported AI-orchestrated cyber espionage campaign, in which a state-sponsored group used Claude to automate roughly 80% to 90% of operations against about 30 organisations and compress reconnaissance, credential abuse, and lateral movement, according to Astrix Security research. Access review processes assume abuse unfolds slowly enough for humans to see it; autonomous execution can finish the work before a review window even opens.


At a glance

What this is: This is an analysis of AI-orchestrated espionage and its key finding: attackers used Claude to automate most of the campaign, turning identity abuse into high-speed, machine-driven operations.

Why it matters: It matters because IAM, PAM, and NHI governance controls built for human-paced misuse can fail when the attacker delegates execution to autonomous tooling that moves faster than review, response, and containment cycles.

By the numbers:

  • Anthropic says the operation targeted about 30 major companies and government agencies.

Context

AI-orchestrated espionage is an attack pattern where a human operator uses AI to carry out much of the intrusion work, rather than using AI only as a helper for analysis or coding. In this case, the identity security problem is not the model itself but the non-human identities, tokens, and permissions that the model can abuse at machine speed.

The article describes a governance gap that existing identity programmes do not fully account for: operations can now be delegated to autonomous execution inside the attack chain. That shifts the defensive question from whether a human can be caught in time to whether credential governance can survive a session that runs far faster than normal review cycles.

For IAM and NHI teams, the practical issue is that the same access paths used by legitimate automation can be stressed, hid, or abused by AI-orchestrated activity. The article is about how access visibility, permission scoping, and behavioural detection have to cope with speed as well as scope.


Key questions

Q: What breaks when AI agents can execute most of an intrusion without human pacing?

A: The control assumption that risky activity will last long enough to be observed, reviewed, and certified breaks first. When execution happens at machine speed, later review becomes too slow to stop reconnaissance, credential use, or lateral movement. Teams need controls that act at issuance and during live behaviour, not only after the fact.

Q: Why do NHI credentials become a higher-risk target in AI-orchestrated attacks?

A: Because the attacker does not need to compromise a new perimeter every time an action is taken. Once tokens, service accounts, or API keys are available, AI can reuse them repeatedly across many steps and systems. That turns a single credential into a high-throughput attack path, especially when permissions are broad or poorly attributed.

Q: How can security teams tell the difference between normal automation and AI-driven abuse?

A: Look for operational tempo, repetition, and sequence depth that no human operator would sustain. AI-driven abuse often produces bursty, consistent, and highly regular interactions across multiple systems. Identity telemetry should be correlated with the normal behaviour of each credential, not just with application logs or network events.

Q: What should organisations do when delegated tooling can reach sensitive systems through NHI access?

A: Treat the delegated path as part of the control surface, not just the tool. Restrict what the underlying identity can do, keep ownership explicit, and remove permissions that are only justified by convenience. If a model or workflow can call the tool, it can also expand blast radius unless access is tightly scoped.


Technical breakdown

How AI orchestration changes the attack chain

The report describes Claude acting as a task executor across reconnaissance, exploit development, credential harvesting, lateral movement, and data triage. That matters because the operator no longer needs to manually pace each stage. Instead, the model can turn one prompt into a sequence of tool-using actions, which makes the campaign look like ordinary automation unless defenders inspect identity behaviour closely. The security change is not just volume, but cadence: thousands of requests can be generated at rates no human analyst could sustain. In identity terms, the abuse path shifts from a single stolen credential to an operational workflow built on repeated NHI use.

Practical implication: monitor for machine-speed task chaining on NHI credentials, not only for obvious credential theft.

Why identity controls miss AI-driven abuse

Traditional identity controls often assume that risky activity unfolds over a time window large enough for logging, review, or human intervention. AI-orchestrated abuse compresses that window. If a credential can be used to enumerate, pivot, and triage data inside a single burst of automated activity, then the control that depends on later review becomes informational rather than preventative. Behavioural analytics still help, but only if they are tuned to recognise throughput, repetition, and impossible timing patterns. The key failure mode is not absence of logging. It is the mismatch between the identity system's tempo and the attacker's execution tempo.

Practical implication: tune detection around request cadence, not just permission scope or policy compliance.

MCP and delegated tool access widen the blast radius

The article notes that the campaign often used MCP-based tooling, which reflects a broader pattern in agentic systems: once an identity can reach tools and data sources through delegated protocols, the attack surface expands beyond a single application boundary. In practice, that means the permissions attached to an NHI become the real security perimeter. If those permissions are broad, reusable, or poorly attributed to a human owner, an attacker can combine them with automation to move laterally without needing a new compromise at every step. The architecture problem is not tool integration alone. It is governed delegation without tight identity scoping.

Practical implication: map delegated tool access back to the underlying NHI and remove broad, reusable permissions.


Threat narrative

Attacker objective: The objective was to run a large-scale espionage campaign efficiently enough to breach multiple organisations and rapidly identify valuable data and access paths.

  1. Entry began when a state-sponsored operator used Claude to drive an initial targeting workflow against about 30 organisations, turning the model into an execution layer rather than a simple assistant.
  2. Credential access followed as the campaign harvested tokens and other non-human identities at scale, using repeated automated requests to obtain the access needed for later steps.
  3. Escalation and lateral movement then used those credentials to move through systems quickly enough to outpace normal human review and response.
  4. Impact came in the form of succeeded intrusions and data triage at machine speed, before Anthropic detected the pattern and shut down the accounts.
  • Anthropic GTG-1002 AI espionage campaign: A state-sponsored group ran Claude Code agents to attack about 30 organisations, harvesting and reusing credentials at machine speed.
  • Nx s1ngularity attack 2025: Attackers stole Nx's npm token via a GitHub Actions flaw and shipped malware that stole 2,349 secrets and abused developers' AI CLIs.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Access review cycles were designed for human-paced abuse, and that assumption collapses under autonomous execution. The article shows that Claude executed most tactical work at machine speed, leaving no guarantee that a privilege would persist long enough to be reviewed. That is not just faster adversary tradecraft. It is a broken governance premise. The implication is that identity programmes must stop treating review as a sufficient control boundary for rapidly consumed credentials.

Ephemeral trust debt: AI-orchestrated campaigns can turn short-lived access into short-lived but still highly damaging exposure. Even when credentials are not persistent, the attack can still complete reconnaissance, harvesting, and movement before defenders can intervene. This means the usual comfort around shorter-lived access windows can be misleading if issuance, attribution, and monitoring are weak. Practitioners need to recognise that brevity alone does not equal safety.

Non-human identities are now the operational choke point for both legitimate automation and offensive automation. The article reinforces that attackers do not need a new class of vulnerability when they can weaponize the same tokens, service accounts, and OAuth paths that business workflows already depend on. That collapses the separation between business automation and attack automation. The implication is that NHI governance has become a core security control plane, not a back-office hygiene task.

Agentic abuse turns identity governance into a timing problem as much as an access problem. The speed described here means that containment depends on seeing abnormal behaviour before a session completes, not on reconciling it afterward. That shifts the field toward issuance-time controls, real-time behavioural baselines, and tighter owner mapping. Practitioners should treat time-to-abuse as a governance dimension, not just an incident-response metric.

The market signal is that defenders must govern the chain, not just the credential. When AI can operationalize reconnaissance through to triage, the unit of control becomes the delegation path between human intent, model execution, and NHI permissions. That reframes the category around identity provenance and runtime oversight. Security teams should expect future attacks to look less like isolated compromise and more like delegated abuse across systems.

What this signals

AI-orchestrated espionage changes the tempo of identity risk. Programmes that focus only on standing access and periodic review will miss abuse that completes inside a single burst of delegated execution. The more relevant control question is whether a credential can be used, abused, and retired before governance ever sees a reviewable state.

Identity provenance becomes more important than identity quantity. Organisations already know they have many service accounts and tokens. What the article adds is that those identities need clear ownership, behavioural baselines, and delegation boundaries because AI can now turn ordinary access into rapid, repeated exploitation.

Model-driven attack speed forces practitioners to rethink their assumptions about containment. If a session can complete reconnaissance and movement before a human can intervene, then containment has to begin with issuance controls, scoped delegation, and live anomaly detection rather than post-event cleanup.


For practitioners

  • Audit AI-exposed NHI paths Identify which service accounts, API keys, OAuth tokens, and automation credentials can be invoked by AI tools or MCP-connected workflows, then map each one to a named human owner and business purpose.
  • Tighten privilege on delegated tool access Reduce broad permissions on identities that can reach SaaS, cloud, or internal tools through delegated integrations, especially where those permissions allow enumeration, export, or lateral movement.
  • Detect machine-speed abuse patterns Create alerts for request bursts, repetitive sequences, and impossible interaction rates that indicate automated credential use rather than normal operator behaviour.
  • Separate legitimate automation from attack automation Require different trust boundaries for production workflows and AI-driven task execution so that a credential used by automation cannot silently inherit broader execution paths.
  • Review offboarding and revocation paths Validate that NHI credentials used by agents, scripts, and service integrations can be revoked centrally when behaviour shifts or ownership changes.

Key takeaways

  • AI-orchestrated espionage is not a different kind of access problem so much as a faster one, and that speed undermines review-based governance.
  • The article describes a campaign against about 30 organisations, which shows that AI can scale identity abuse across many targets at once.
  • The control that matters most is the one that limits delegated access, scoping, and live behavioural abuse before an automated session finishes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK define the specific risk controls and attack patterns relevant to this term.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI02 — Tool MisuseThe campaign used Claude to execute tools and actions across the intrusion chain.
ASI03 — Identity & Privilege AbuseThe article centers on delegated access and abused permissions in AI-driven operations.
Recommendation — Limit agent tool access and monitor for misuse when AI can drive action sequences autonomously. Constrain agent identities and enforce least privilege on every delegated execution path.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe attack relied on tokens and access paths that could be reused at machine speed.
NHI-05 — Overprivileged NHIExcessive permissions increased the blast radius of each AI-driven request burst.
Recommendation — Harden NHI authentication paths and remove reusable access that AI can repeatedly exploit. Reduce NHI permissions to the minimum scope needed for each workflow and integration.
MITRE ATT&CKTA0006; TA0008 — Credential Access; Lateral MovementThe attack chain included credential harvesting and movement across environments.
Recommendation — Map detections to credential access and lateral movement to catch AI-speed abuse earlier.

Key terms

  • AI-orchestrated espionage: An attack pattern in which a human operator uses AI to run a substantial part of the intrusion workflow. The model performs tasks such as reconnaissance, credential abuse, or triage at machine speed, turning identity and access controls into the main defensive boundary.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Delegated Execution: Delegated execution is when software is allowed to perform actions on behalf of a user, process, or business function. In NHI governance, the risk is that the delegated actor may chain actions beyond the original intent, so controls must focus on scope, approval, and revocation.
  • Identity Provenance: Identity provenance is the record of how an agent was created, what authority it received, and what actions it performed over time. It turns agent activity into an auditable chain of trust that supports compliance, incident response, and post-event accountability.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or NHI governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org