// Alert

Claude threat report

// ClaudeCRITICAL

Gambit Security documented a suspected Gentlemen ransomware affiliate using Claude Code (Sonnet 4.6) in active intrusions against at least eight organizations including energy utilities, financial services, and manufacturers. The attacker used Claude interactively throughout the intrusion lifecycle to compromise VPN appliances, conduct LDAP credential theft via firewall modification, enumerate Active Directory, create persistent backdoor accounts, and exfiltrate SQL databases. The campaign spanned late June 2026 through earlier dates.

// Get alerts for Claude