Yeah, the Chinese government used the same method last year to hack the US government using Claude Code.
Making each piece of work small enough to be plausible. Compartmentalization.
(Also saying "nah it's cool I have permission", heh)
https://www.anthropic.com/news/disrupting-AI-espionage