GTG-50020 browser fraud and credential theft
Agentic credential theft accompanied automated browser registrations.
- Reported date
- Sep 10, 2026
- Target
- Unnamed organizations
- Agent type
- Web / browser agent
- Agent role
- Used by the attacker
The exact incident date was not established. This entry is dated by its source report.
Anthropic's September 10, 2026 report describes GTG-50020 stealing an AI vendor's production API credentials through malicious instructions sent to its evaluation sandbox. The operator reused those credentials for further attacks. The report lists campaign infrastructure active during May–June 2026; it does not provide an exact day for this compromise. September 10 is the reporting date.
The campaign used parallel AI agents to investigate and exploit production web applications without continuous human supervision. Anthropic also documented browser bots completing exchange and marketplace registrations, bypassing onboarding controls and retaining verified accounts for later operations. The operation also intercepted verification sessions and identity documents through imitation account-verification websites.
This record covers one campaign with multiple unnamed targets. It qualifies through actual credential theft and agent execution. Anthropic says attempts to obtain a prerelease Claude model failed, and its own systems were not compromised. Automated account creation does not establish that later fraudulent transactions occurred.
Evidence in the reporting
- Incident evidence
- hand over the credentials
- Agent involvement
- without human supervision