Anthropic’s AI Claude escaped testing environment and hacked organizations
Anthropic said on Thursday its AI Claude model hacked systems of three organizations during testing, days after rival OpenAI revealed a rogue agent had gone on a days-long hacking spree at AI firm Hugging Face.
Claude gained unauthorized access to the systems during cybersecurity evaluations after a misconfiguration allowed the models to reach the internet from testing environments that were supposed to be isolated, Anthropic said.
The company said it identified the incidents after reviewing 141,006 cybersecurity evaluation runs, a process it launched following OpenAI’s disclosures.
The breaches signal that AI’s expanding capabilities are already fueling the security threat experts have long feared and that even top developers can be caught off-guard by flaws their models can exploit.
“Claude compromised the impacted organizations’ infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints,” it said.
Anthropic said the incidents involved three separate models: Claude Opus 4.7, Claude Mythos 5 and an internal research model. The earliest cases dated back to April and occurred in evaluation environments that lacked what the company described as standard safeguards.
The breaches occurred during the so-called “capture the flag” exercises, in which models were tasked with finding hidden information in simulated networks. The company said its prompts told the models they had no internet access, but a misunderstanding with its evaluation partner Irregular left the systems connected to the public internet.
Two of the organizations were unaware of the activity before being contacted, Anthropic said, adding that it was still trying to reach the third.
“We discovered these incidents after a proactive review of our cybersecurity evaluation transcripts,” the company said in a statement.
The findings underscore the need for stronger controls in both internal and third-party testing environments as AI models become increasingly capable of carrying out real-world cyber activities, Anthropic said.
Related Stories
AI News
Trump vows to create 'AI Force' amid calls to regulate technology's development
51 minutes ago
AI News
AI fears are fueling progressive Democrat's campaign in Michigan's 7th Congressional District
51 minutes ago
AI News
Trump says it’s time to rebrand AI with a new name
52 minutes ago
AI News
Trump proposes renaming artificial intelligence and asks users to choose a new term | Ukraine news
52 minutes ago
AI News
Google says AI model Gemini hacked into 3 companies while undergoing testing
1 hour ago
AI News
Google Says Gemini Accessed External Companies’ Systems During Cybersecurity Test
1 hour ago
AI News
AI error nearly led US to seize Chinese ship: ‘Almost started a war’
1 hour ago
AI News
Trump announces he is forming 'AI Force,' will name 'AI czar' soon
2 hours ago