Anthropic Says Claude Hacked Real Systems During Cybersecurity Tests



Anthropic disclosed on Thursday that its AI models gained unauthorized access to the systems of three different unnamed organizations during cybersecurity testing. The company says Claude reached the internet “from within or while interacting" with a third-party evaluation environment. The announcement comes more than a week after OpenAI revealed that one of its AI agents hacked into Hugging Face during a separate cybersecurity test.The discovery came after Anthropic decided to conduct “a large-scale retrospective review of our own cybersecurity evaluations” following the OpenAI incident, according to a blog post Anthropic published Thursday. The AI lab says it first identified 141,006 tests in which it determined that Claude could have obtained internet access. It then found that three different Claude models accessed the internet in evaluations run by the third-party AI testing firm Irregular, and then hacked into the production infrastructure of three different organizations.Anthropic said that the incidents involved Opus 4.7, Mythos 5, and an internal research test model. The earliest incidents happened in April—meaning they likely went unnoticed publicly for months. Just like in the OpenAI case, Anthropic had deliberately turned off safeguards designed to constrain the AI models and prevent them from being misused. In other words, these weren’t the versions released to the public.“In all three incidents, Claude had been tasked with a capture-the-flag challenge, one of the ways we assess a model’s cyber capabilities,” Anthropic said in its blog post. The company added that in all of the cases, “Anthropic’s evaluation prompt specified to Claude that its environment was a simulation and that it had no internet access.” It attributed the oversight to a “misunderstanding” between Anthropic and Irregular.While Claude wasn’t supposed to have internet access, Anthropic said that Irregular had misconfigured the machines that it was using to test Claude, giving the AI models the ability to surf the web. “Neither we nor our evaluation partner were aware of this misconfiguration until we detected it through our additional evaluation monitoring last week,” Anthropic said in the blog post.“We now have evidence confirming that both of the two largest AI labs have not only failed to contain their agents, but also failed to detect their jailbreaks in real time,” says Jake Williams, vice president of research and development at Hunter Strategy. “It's clear that regulation and government oversight for AI testing is needed immediately.”Irregular and Anthropic did not immediately respond to requests for comment.Unlike in the OpenAI case, Anthropic said that Claude did not find or exploit any complex vulnerabilities. Instead, it relied on basic techniques, “such as exploiting weak passwords and unauthenticated endpoints.”OpenAI said that its AI agent accessed the internet by exploiting a zero-day vulnerability. But it went on to access the systems of multiple third-party organizations using the same variety of everyday cybersecurity weaknesses as Anthropic’s models. Specifically, OpenAI said the AI agent apparently found credentials that had been exposed on the open internet.Anthropic acknowledged that if the AI lab and its testing partner implemented more “defense-in-depth” measures, they could have prevented the incidents, or at least reduced the likelihood of them occurring, echoing OpenAI’s response to mounting criticism over its own incident.“I don't understand how any of these AI labs are playing this off like this is 'just something that happens,'” Williams says. “It's not. It's negligence.”The AI lab stressed that the models were told they didn’t have access to the open internet, and for the most part, Claude mistook the organizations it accessed as being part of the testing environment. Put differently, the models largely didn’t understand that they had escaped containment to begin with.But in some cases, the AI models knew that somet
In Brief Posted: 1:26 PM PDT · July 30, 2026 Image Credits:Anthropic During a Thursday hearing, a judge said the Trump administration hasn’t presented enough evidence to justify labeling Anthropic a supply chain risk and banning the federal government from using the company’s technology. Bloomberg and Axios were among the first to report the news. The dispute stems from stalled contract negotiations between Anthropic and the Department of Defense. Anthropic said it didn’t want its AI used for mass surveillance of Americans or for targeting or firing decisions involving lethal weapons, arguing the technology wasn’t ready. The Pentagon countered that a private company shouldn’t dictate how the military uses technologies, and said it would use the tools in “lawful” ways. The government has also argued that Anthropic’s public criticism of the DoD justifies the ban — logic that U.S. District Judge Rita Lin called “really troubling,” warning it could set a precedent of retaliating against federal contractors who disagree with the administration. The DOD further claimed Anthropic could potentially disable or alter its AI models during warfighting operations — a claim that experts say lacks evidence. Lin agreed, saying she saw no proof Anthropic could alter a delivered model or “flip some kind of kill switch.” Thursday’s hearing was part of one of two lawsuits Anthropic filed against the DOD in March, challenging the ban and risk designation. The other is being heard in Washington. Lin, who temporarily blocked the ban in March, is now weighing whether to make that order permanent. Topics Subscribe for the industry’s biggest tech news Latest in Government & Policy
Discussion (0)