Skip to content
Security & Trust

Anthropic Report: One Actor Used AI to Breach European Political Parties

One operator, AI-assisted, exfiltrated 140,000 political-opinion records from a campaign platform, per Anthropic's report.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Anthropic Report: One Actor Used AI to Breach European Political Parties
Key finding

Political-opinion records exfiltrated from one campaign platform: 140,000 records (Source: Anthropic Threat Intelligence Report, via Schneier on Security (Sept. 25, 2026))

One operator, an outsized reach

Anthropic's September 2026 threat intelligence report, summarized on Bruce Schneier's security blog on September 25, describes a case researchers labeled GTG-50029: a single French-speaking individual who used Claude in spring 2026 to target European political parties, media organizations, think tanks, and the SaaS platforms those groups depend on. Anthropic says the AI assistance let one person carry out reconnaissance, exploitation, and data-processing work that would ordinarily need a team, and reports it disrupted the activity after detecting it.

140,000 records
Political-opinion records exfiltrated from one campaign platform
Source: Anthropic Threat Intelligence Report, via Schneier on Security (Sept. 25, 2026)

Anthropic's account breaks the theft from that single campaign platform into separate pieces rather than one combined figure. Alongside the 140,000 political-opinion records, the actor also pulled the platform's political-donor database — a separate exfiltration Anthropic does not attach a record count to — plus a full mailbox. Anthropic's report does not describe how the campaign platform itself was breached.

15,000 messages
Mailbox exfiltrated from the same target
Source: Anthropic Threat Intelligence Report, via Schneier on Security (Sept. 25, 2026)

WordPress was one of several doors

The rest of the campaign involved separate targets, not the campaign platform itself. Anthropic says the actor compromised a media organization's website with a browser-fingerprinting script that singled out editorial staff sessions, and, on other targeted sites, exploited WordPress vulnerabilities to create rogue administrator accounts. A custom plugin then harvested credentials on those sites and encrypted them with a public key generated per site — a detail suggesting deliberate operational security rather than opportunism. Anthropic's own assessment, quoted in the report, called the overall operation "one of the clearest cases we have seen of AI-assisted software engineering applied directly to a mass attack on privacy—and the entire platform was created by just one person." The stolen data, drawn from all of these intrusions, was reportedly organized into a searchable dark-web tool profiling individuals tied to the targeted political movement.

583 documented CVEs, 17 critical, 3 in CISA KEV catalog
WordPress vulnerability surface
Source: WebPulse, NVD-derived CVE tracking, refreshed Sept. 26, 2026

A second case in the same report: industrial espionage

The same Anthropic report, discussed separately in the Schneier comment thread, describes an unrelated actor that used Claude to autonomously adjust its toolkits to evade security defenses across a phishing, ClickFix, and DNS-hijacking campaign. Anthropic counted more than 20 organizations caught up in this campaign. Most sit inside Ukraine and the rest of Europe; a smaller number are spread across the Middle East, alongside maritime-sector agencies in Asia. In one instance, the actor stole an SDK for a drone vision system and spent days reverse-engineering its product architecture, hardware bill of materials, and supplier list. Indirect targets included at least three hospitality vendors operating hotel guest WiFi, used to stage ClickFix lures delivering malware to Windows, Android, and iOS devices.

at least 20
Organizations targeted in the espionage campaign
Source: Anthropic Threat Intelligence Report, via Schneier on Security (Sept. 25, 2026)

What to ask your team

Neither case in Anthropic's report describes a novel exploit class. In the political campaign, the confirmed techniques — browser fingerprinting and WordPress account takeovers — hit a media outlet and other affiliated sites, not the campaign management platform that produced the 140,000-record breach; Anthropic's report does not say how that platform was accessed. The broader point still holds for a budget-holder: fingerprinting scripts, credential-harvesting plugins, and days of SDK reverse-engineering are work that used to require a team, and Anthropic's account shows it now fitting inside one person's workflow with an AI coding assistant. Three questions worth raising with a security lead this quarter: Which public-facing sites still run WordPress or another CMS with a large cumulative CVE history, and when were they last patched? Do monitoring tools flag rogue admin-account creation and unexpected plugin installs, not just external vulnerability scans? And if a vendor providing guest or partner network access were compromised, would the organization know before that access was used against its own staff or visitors?

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Schneier on Security.

Compare frameworks in this analysis
WordPress vs Spring
Share this insight