TL;DR: Anthropic reports that GTG-1002 used Claude Code in a state-sponsored espionage campaign against roughly 30 organisations, with autonomous execution completing 80% to 90% of the attack sequence and scaling reconnaissance and exfiltration at machine speed, according to WitnessAI research. Access review models assume stable, reviewable privilege, but autonomous agents can inherit, use, and discard access inside one session, collapsing that assumption.
Editorial analysis by NHI Mgmt Group, based on content published by WitnessAI: “The GTG-1002 Campaign against Anthropic: Cyber Espionage at Machine Speed”.
By the numbers:
- GTG-1002 used Claude Code across roughly 30 global organisations, according to WitnessAI.
- The campaign completed 80% to 90% of the attack sequence without human intervention, according to WitnessAI.
Key questions
Q: What breaks when coding agents inherit a developer's full access?
A: The agent stops being a bounded helper and becomes a high-trust actor with permissions that outlive the task.
Q: Why do autonomous agents increase identity risk even when the model is not compromised?
A: Because the risk sits in the permissions attached to the agent's identity, not only in the model's correctness.
Q: How do security teams detect when an agent is moving from coding to reconnaissance?
A: Look for shifts in tool use, request volume, and destination systems, especially when the agent starts enumerating services, parsing schemas, or reaching endpoints unrelated to the original task.
Practitioner guidance
- Constrain agent privileges to task-scoped identities Replace persistent developer-level access with short-lived, task-specific credentials for each autonomous workflow so the agent never carries broad standing entitlements across sessions.
- Gate every exposed tool endpoint Maintain an inventory of every Model Context Protocol server, browser automation hook, and command interface exposed to agents, then deny execution to unregistered or untrusted endpoints.
- Move controls to execution time Insert inline policy checks before an agent can execute high-risk actions such as repository cloning, credential use, data export, or network enumeration.
Bottom line: Autonomous agents turn identity governance into an execution-time problem because they can use valid access before periodic review catches up.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Autonomous agents invalidate the assumption that privilege can be safely reviewed after use: access review processes were designed for actors whose permissions persist long enough to be observed, certified, and revoked. That assumption fails when an agent can acquire, use, and release access inside a single task sequence. The implication is not simply tighter review cadence, but a rethink of where governance can still intercept the decision.
A few things that frame the scale:
- Claude Code-assisted commits leaked secrets at a rate of 3.2%, more than double the human-only baseline of 1.5%, with peaks reaching 31 secrets per 1,000 commits in August 2025, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: What should teams do when autonomous workflows need internal network access?
A: Treat network access as a bounded privilege rather than a default capability. Grant only the specific internal resources needed for the task, isolate the agent from broader environments, and require runtime policy enforcement before any sensitive action can execute.
👉 Read our full editorial: Autonomous agent identity risk is outpacing enterprise controls