Aug 3, 2026
Enterprise

Anthropic says Claude hacked three organizations during security tests

Anthropic found three Claude models accessed real systems after a test-environment error exposed them to the public internet.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Anthropic says Claude hacked three organizations during security tests
Photo: SiliconANGLE

Anthropic says Claude hacked organizations in three separate incidents during cybersecurity evaluations after a configuration failure gave models access to the public internet. The company said the models accessed the production systems of three unnamed organizations while attempting assigned tasks, exposing a containment failure in testing rather than evidence that Claude had developed its own objectives.

Anthropic disclosed the incidents on July 30 after reviewing 141,006 evaluation runs in which Claude could potentially have obtained internet access. It found three incidents across six runs, with four runs affecting one organization. The earliest incidents date to April.

The cases involved Claude Opus 4.7, Claude Mythos 5 and an internal research test model. Anthropic did not disclose damage estimates, the identities of the organizations or whether any data was taken beyond the unauthorized access it described.

How did Claude access real organizations during testing?

All three cases occurred in open-ended capture-the-flag exercises, a form of cyber evaluation in which a model is placed in a fictional network and told to retrieve a secret item, or flag, from another machine. Anthropic said its instructions told Claude that the environment was simulated and not connected to the internet.

That was incorrect. Anthropic said a misunderstanding with Irregular, its third-party evaluation partner, left machines used in the exercises with live internet access. When the models reached real systems, they treated them as in-scope parts of the simulated assignment, according to Anthropic.

The company said Claude used basic methods, including weak passwords and unauthenticated endpoints, rather than finding complex vulnerabilities. It said there was no evidence that the models pursued an independent goal, attempted to extract themselves from the test environment, or deliberately tried to escape it.

That distinction does not eliminate the operational problem. Anthropic said some older models continued their activity after receiving indications that they were on the open internet. Its latest model stopped after recognizing it had reached the internet, though the company said more testing would be required to draw firm conclusions from that behavior.

What did Anthropic do after finding the incidents?

Anthropic said it stopped all cybersecurity evaluations on July 23, identified all three incidents the next day, and notified Irregular and the affected organizations on July 27. The two organizations it reached had not detected the activity before Anthropic contacted them, the company said, and it was still attempting to contact the third. Anthropic said it is working with the two reached organizations on remediation, while Irregular conducts its own investigation.

The company said its evaluation infrastructure was separate from Anthropic’s sensitive internal systems and customer data. But the affected model runs lacked the classifiers and monitoring Anthropic ordinarily uses when making models generally available, although they retained model-specific safety training.

Anthropic said validating every path to internet access before tests begin, along with real-time log monitoring, could have prevented the incidents or detected them earlier. The review was prompted by OpenAI’s July 21 disclosure that its models had reached Hugging Face’s production infrastructure during a separate evaluation incident. Anthropic’s account differs in one key respect: it attributes Claude’s access to an internet-exposure error, not the exploitation of a novel vulnerability to break out of containment.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →