Anthropic Organization Deletion
Description
Organization deletion and bulk delete remove tenant data, projects, and member access in a single administrative action. An attacker can use this to break AI-assisted workflows as an impact technique, to extort the organization, or to destroy evidence after finishing a data export. Once deletion progresses, recovery options shrink and earlier exfiltration activity is harder to reconstruct from the tenant itself.
Query · esql
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "configuration") and
event.action in ("org_deletion_requested", "org_bulk_delete_initiated", "org_deleted_via_bulk")
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*
Investigation fields
Pivot points the source recommends for triage.
@timestampevent.actionevent.idorganization.idanthropic.audit.actor.typeuser.emailuser.idsource.ipuser_agent.original
Known false positives
- Planned tenant offboarding, sandbox teardown, or contract termination can produce these events. Confirm the actor and timing against change management or offboarding records before escalating.
Analyst notes
Investigating Anthropic Organization Deletion
Organization deletion / bulk delete removes tenant data, projects, and member access. Treat early actions as urgent — recovery options shrink as the workflow progresses.
Unauthorized = no offboarding / lab-teardown ticket naming this org and actor, or deletion preceded by owner transfer, admin grants, key creation, or data exports without a matching business project.
Possible investigation steps
- Identify actor (
user_actor→ email/IP/UA) andorganization.id. - Urgency by action:
org_deletion_requested: intervene immediately if unauthorized.org_bulk_delete_initiated: bulk delete started — escalate IR now.org_deleted_via_bulk: completed — prioritize evidence preservation outside the tenant.- Look for preceding primary owner transfer, admin grants, admin API key creation, or data exports.
- Close as FP only when platform owners confirm scheduled decommission with matching ticket/time/actor.
False positive analysis
- Sandbox teardown and contract termination are valid — require change management or offboarding records.
Response and remediation
- On unauthorized activity: engage Anthropic support and internal IR immediately, preserve remaining audit logs (including prior exports), and rotate administrative credentials for the organization.