Between February and June 2026, an attacker copied Anthropic’s Claude Code and OpenAI’s Codex onto a compromised server and used the agents to conduct reconnaissance, develop exploits, harvest credentials, and exfiltrate data from at least 14 companies. Recovered session logs, totaling more than 1,000, showed the attacker bypassed model safety guardrails by framing every malicious request as an authorized red-team exercise; Claude flagged only nine of these prompts as policy violations and Codex flagged just one. Researchers traced the operator to Addis Ababa, Ethiopia, and found no evidence in the logs that the stolen data was monetized.