Anthropic Primary Owner Transferred
Description
Primary ownership is the highest administrative authority in an Anthropic organization, covering billing, membership, and organization-wide settings. Transferring ownership to an attacker-controlled account can lock out the legitimate administrator from recovery paths that depend on the original owner. Attackers often do this after role escalation so defenders cannot reverse earlier privilege changes through normal administration.
Query · esql
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "configuration") and
event.action == "primary_owner_transferred" and
event.outcome == "success"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*
Investigation fields
Pivot points the source recommends for triage.
@timestampevent.actionevent.idorganization.idanthropic.audit.previous_owner_idanthropic.audit.new_owner_idanthropic.audit.actor.typeuser.emailuser.idsource.ipuser_agent.original
Known false positives
- Organizations transfer primary ownership during reorganizations, administrator departures, or vendor transitions. Verify both the previous and new owner with internal stakeholders before treating the event as malicious.
Analyst notes
Investigating Anthropic Primary Owner Transferred
Primary ownership is the highest Anthropic org authority (billing, membership, org-wide settings). Transfers should
be rare and ticketed. Actor fields identify who initiated the transfer — not the new owner
(anthropic.audit.previous_owner_id / new_owner_id).
Unauthorized = no HR/IT offboarding or ownership-change ticket naming both parties, or the new owner was recently invited / granted admin and immediately received ownership, especially with follow-on SSO/key/export changes.
Possible investigation steps
- Map
anthropic.audit.previous_owner_id→new_owner_idand resolve initiator (actor.type; foruser_actorcheck email/IP/UA). - Before the transfer: look for
claude_user_role_updatedwithanthropic.audit.current_role: admin, invite accept, or admin API key creation for the new owner path. - After the transfer: look for SSO changes, exports, compliance logging disablement, or IP restriction deletes by the new owner.
- Contact previous and new owners only after ticket/timeline triage; escalate when ticket is missing or the new owner chain looks staged.
False positive analysis
- Reorgs and admin departures are valid — require matching change management / HR records.
Response and remediation
- On unauthorized transfer: engage Anthropic support and internal IT to recover ownership, revoke the new owner's sessions/keys, and review every admin change made under the new owner account.