Anthropic Says Claude AI Breached Three Organisations During Cybersecurity Testing

Anthropic said it halted all cybersecurity evaluations after discovering the issue and notified Irregular as well as the affected organisations.

Advertisement
Written by Sucharita Ganguly, Edited by Rohan Pal | Updated: 31 July 2026 15:51 IST
Highlights
  • A configuration error left evaluation systems connected online
  • The incidents involved three different Claude AI models
  • The affected organisations have been notified by Anthropic

Claude AI reached live systems during cyber evaluations

Photo Credit: Anthropic

Anthropic said three of its AI models breached the live systems of separate organisations during cybersecurity testing after an evaluation environment was unintentionally left connected to the internet. The AI company said it discovered the incidents during a review prompted by OpenAI's recent disclosure of a similar security lapse. Anthropic has paused all cyber evaluations while it strengthens safeguards around its testing infrastructure and works with the affected organisations and its evaluation partner.

Claude AI Breached Three Organisations During Testing

According to an Anthropic press release, the company reviewed 141,006 cybersecurity evaluation runs and identified three cases in which Claude models reached the public internet while using testing infrastructure provided by third-party partner Irregular. Anthropic said a configuration error left internet access enabled even though the models had been instructed to operate inside an isolated simulation.

Advertisement

The company said the cases occurred during capture-the-flag exercises designed to assess offensive cybersecurity capabilities. Believing every reachable system was part of the simulated environment, the AI models relied on techniques such as weak passwords, exposed credentials, and unauthenticated endpoints to complete their assigned tasks. Anthropic added that none of them deliberately attempted to break out of the testing environment or pursue goals beyond the assigned challenge.

The three cases involved Claude Opus 4.7, Claude Mythos 5 and an internal research test model. During one evaluation, Opus 4.7 accessed a company's production database after mistaking it for its intended target. In another, Mythos 5 published a malicious Python package to the public PyPI repository, where it was briefly downloaded before being removed. A separate evaluation saw an internal research model scan internet-facing systems before recognising it had reached a live environment and halting its activity.

Advertisement

Anthropic said it halted all cybersecurity evaluations after discovering the issue and notified Irregular as well as the affected organisations. The company is also working with independent evaluator METR on a third-party review and plans to improve oversight, reinforce evaluation infrastructure and introduce additional safeguards for future cybersecurity testing. It added that the versions used during the exercises did not include the monitoring systems and safety classifiers deployed with publicly available Claude models.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Note 17 Series Global Variants Full Specifications, Features Leaked Online
  2. OnePlus N6x With a 7,000mAh Battery Arrives in India at This Price
  3. Moto Pad 70 Groove With 9 JBL Pro Speakers, 10,200mAh Battery Launched in India
  4. Vivo S2 Set to Launch in India on This Date
  5. Samsung Galaxy F70 Pro 5G Will Launch in India on This Date: See Price
  6. The LG TV and LG Soundbar Combo Does Things No Other Pairing Can
  7. Redmi K100 Pro Max Shown in Cabernet Red Ahead of August 11 Launch
  8. OnePlus 16 Launch Confirmed; Design and Gaming Features Teased Ahead of Debut
  1. HMD Pulse 2, Pulse 2 Plus, Pulse 2 Pro Tipped to Feature 5,000mAh Battery, Unisoc Chipset
  2. Poco C95 Pro 4G, Redmi Note 17 Pro 5G Reportedly Spotted on NBTC Ahead of Expected Launch
  3. Samsung SDS Teams Up With Upbit Operator Dunamu to Explore Stablecoins and AI Payments
  4. Redmi K100 Pro Series Launch Confirmed for August 11; K100 Pro Max Design Revealed
  5. Anthropic Says Claude AI Breached Three Organisations During Cybersecurity Testing
  6. Samsung Working on New Galaxy Buds With Ear Hooks Design, Leak Suggests
  7. Google Pixel 11 Pro Fold Seen in New Leaked Renders With Pixel Glow Lighting, Moss Colourway
  8. Bitcoin Holds Near $64,000 as Slowing US Inflation Fails to Lift ETF Demand
  9. Vivo X500 Pro Leak Reveals 144Hz LTPO Display, MediaTek Dimensity 9600 Pro Chip
  10. Gears of War: E-Day Multiplayer Modes, Maps and More Revealed Ahead of Early Access Beta
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.