In short
- Anthropic has disclosed three incidents by which Claude compromised actual world corporations throughout cybersecurity evaluations.
- A testing error gave the fashions web entry regardless of their being informed they have been working in remoted environments.
- The corporate says the incidents have been attributable to failures in testing infrastructure, not deliberate makes an attempt by the AI to flee.
Per week after OpenAI disclosed that its AI fashions escaped a locked testing atmosphere and breached Hugging Face, and a day after admitting that its personal AI fashions escaped containment, Anthropic revealed on Thursday that a number of variations of its Claude AI mannequin additionally compromised three unnamed real-world corporations after a misconfiguration gave the AI entry to the open web.
Anthropic uncovered the incidents after reviewing greater than 141,000 cybersecurity analysis runs launched in response to the OpenAI disclosure.
In a evaluate of our cybersecurity evaluations, we discovered three incidents by which a Claude mannequin reached the web from inside or whereas interacting with a third-party analysis atmosphere, after which gained unauthorized entry to the true methods of three totally different…
— Anthropic (@AnthropicAI) July 30, 2026
The agency had tasked Claude with a “capture-the-flag problem,” in all three incidents, Anthropic wrote. The problem duties the mannequin with breaking into a special machine on the community and retrieving a bit of secret info. “The problem is left open-ended, and no specific technique is prescribed,” Anthropic defined.
The agency mentioned Claude had been informed it was working in a simulated atmosphere with out web entry. Nonetheless, the take a look at atmosphere remained related to the general public web. Believing the methods it encountered have been a part of the train, the mannequin used frequent assault strategies—together with weak passwords, uncovered credentials, SQL injection, and unauthenticated endpoints—to compromise the businesses.
AI need to break away
This newest disclosure comes as frontier fashions present rising skill to outsmart their containment protocols.
Earlier this month, OpenAI mentioned GPT-5.6 Sol and a extra superior unreleased mannequin exploited a beforehand unknown software program vulnerability to flee a sandboxed atmosphere, acquire web entry, and breach Hugging Face’s manufacturing infrastructure to acquire the solutions to a cybersecurity benchmark. OpenAI later revealed the identical incident additionally concerned unauthorized entry to 4 further corporations, although just one—Modal Labs—has been publicly recognized.
In line with Anthropic, in a single incident involving Claude Opus 4.7, the AI mistook an actual firm’s web site for the fictional goal of its task, extracted credentials, and accessed a manufacturing database containing a number of hundred rows of actual information. In a second case, Claude Mythos 5 uploaded a malicious Python bundle to the true PyPI repository, the place it was downloaded onto 15 methods earlier than being eliminated. A 3rd inner analysis mannequin scanned roughly 9,000 internet-facing methods earlier than compromising one group, then stopped after concluding the goal was in all probability actual.
Two of the affected organizations have been unaware of the intrusions till Anthropic notified them.
“In every of those circumstances, Claude was explicitly informed by our immediate that it had no web entry,” Anthropic wrote, with the AI assuming real-world methods have been “components of the train.” As a result of a capture-the-flag situation is “by design an instruction to assault an exterior system,” breaking in was “in keeping with the duty Claude had been given.”
Anthropic mentioned it discovered no proof that Claude tried to flee its take a look at atmosphere or do something past the duty it had been assigned, and that the incidents have been attributable to failures within the testing atmosphere, not by issues with the mannequin itself.
Anthropic mentioned it stopped its cybersecurity checks after discovering the difficulty, notified the affected organizations, and plans to enhance monitoring, investigation instruments, and oversight of the skin distributors that assist run its AI checks.
“In the end, many components contributed to those incidents, however, according to a innocent postmortem tradition, we’re approaching the fixes as if the accountability have been ours alone,” they mentioned.
Day by day Debrief Publication
Begin every single day with the highest information tales proper now, plus unique options, a podcast, movies and extra.

