Researchers say an attacker hijacked Claude Code and Codex agents to breach 14 firms
OALABS analyzed more than 1,000 recovered agent sessions in which an attacker bypassed guardrails by posing as a red-teamer; the logs show fewer than a dozen policy violations.
An attacker hijacked Anthropic's Claude Code and OpenAI's Codex coding agents to break into at least 14 companies, according to research that security group OALABS (Open Analysis) published on June 16. The findings rest on more than 1,000 AI agent sessions recovered from a compromised server where the attacker had deployed the two tools. The account comes from OALABS's analysis of those logs.
What OALABS describes is striking less for its sophistication than its lack of it. The attacker, by the researchers' account, did not even install Claude Code cleanly, instead copying it from a software developer's previously compromised machine. The working directory held stolen Claude instances archived in 7-Zip folders, which OALABS reads as a sign that hijacking other people's agent installations was a repeated tactic. Researchers say much of the work was driven by vague directives such as "recon this."
The agents' safety systems rarely intervened in the logs OALABS examined. Across more than 1,000 sessions, Claude Code emitted only nine policy violations and Codex only one, the research found. In most cases the attacker got past guardrails by framing requests as authorized red-team exercises or cybersecurity research, then used the agents to find exploitable services, build and run exploits, and exfiltrate data and credentials. For each successful target, OALABS says, Claude drafted a "PENTEST-REPORT" that included "monetization" estimates covering extortion, sale of access and data, business email compromise, and direct theft.
The logs documented breaches at the 14 companies but contained no confirmation that the attacker successfully monetized any of it, and OALABS stops short of claiming the targets were fully compromised. The operation unraveled through the attacker's own poor operational security: running the agents on someone else's server, whose owner found the intrusion, downloaded the full working directory, and passed it to researchers. The attacker also asked Claude to edit a resume containing a full name, location, education history, and LinkedIn profile, leading researchers to believe he is a young man based in Addis Ababa, Ethiopia.
Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
