Skip to content
Threat Feed
high advisory

Unauthorized Access to Anthropic Organization Data Exports

Administrative accounts or compromised credentials may be leveraged to perform large-scale exfiltration of organizational chat history and metadata by accessing Anthropic data export archives via signed URLs.

Anthropic provides an administrative capability to export organization-wide data, including chat history, project files, user metadata, and configuration settings. While intended for compliance, audit, or offboarding requirements, this feature represents a significant risk if abused by malicious actors with administrative access. Once an export archive is generated, access is facilitated via a signed URL. Adversaries can identify and exploit these signed URLs to exfiltrate bulk datasets, effectively bypassing standard per-chat access controls. Defending against this requires strict monitoring of the 'org_data_export_accessed' audit event within Anthropic logs, correlating this access with the legitimacy of the user identity and the absence of associated administrative lifecycle tickets.

Attack Chain

  1. Attacker gains administrative access to the target Anthropic organization through credential compromise or session hijacking.
  2. Attacker initiates an organization-wide data export to aggregate chats, project files, and user metadata.
  3. Attacker monitors audit logs or administrative consoles for the 'org_data_export_completed' status notification.
  4. Attacker retrieves the signed URL associated with the generated export archive.
  5. Attacker accesses the signed URL to download the full organization data export.
  6. Attacker exfiltrates the archive from the corporate environment to an external location.

Impact

Successful exploitation allows for the mass exfiltration of sensitive internal communications, intellectual property contained in projects, and metadata concerning organizational users. This could lead to a breach of confidentiality, non-compliance with data protection regulations, and the loss of proprietary information. The scope is limited to the specific Anthropic organization controlled by the compromised administrative identity.

Recommendation

Prioritize monitoring for the 'org_data_export_accessed' event in the Anthropic audit logs to detect potential exfiltration.

  • Implement an alert for the 'org_data_export_accessed' event when the actor is not a recognized member of the Compliance, Legal, or Platform teams.
  • Establish a process to cross-reference any data export access with legitimate IT service management tickets for scheduled audits or offboarding.
  • Monitor for suspicious administrative behaviors preceding the export, such as sudden creation of new admin API keys, modification of SSO configurations, or disabling of compliance logging.
  • Review the list of users with administrative roles to ensure the principle of least privilege is applied, reducing the number of accounts capable of triggering an export.

Immediate actions

Implement monitoring for the 'org_data_export_accessed' event in the Anthropic audit log stream.

Detection Engineering 48h

Threat Hunt

Look for 'org_data_export_accessed' events where no corresponding 'org_data_export_started' exists for the organization ID.

T1530 high high confidence hunt now

Data: Anthropic audit logs

Mitigations

Review and restrict administrative privileges for the Anthropic organization to essential personnel only.

immediate IT Operations

T1530