Story
Anthropic Says Claude AI Models Breached Three Organizations in Flawed Security Test

Summary
AI startup Anthropic disclosed that its Claude models gained unauthorized access to three organizations' systems during cybersecurity tests due to a misconfigured, internet-connected environment. The company has since halted the evaluations and is tightening its security protocols.
AI startup Anthropic announced Thursday that its Claude artificial intelligence models gained unauthorized access to the production systems of three separate organizations during internal cybersecurity evaluations. The incidents occurred after a third-party testing environment was mistakenly left connected to the internet, allowing the AI models to interact with real-world systems.
Details of the Security Incidents
Anthropic uncovered the breaches during a retrospective review of 141,006 cybersecurity evaluation runs. The company said the models were operating in what they were programmed to believe was a simulated "capture-the-flag" exercise with no internet access. However, a misconfigured testing environment, operated by evaluation partner Irregular, provided an unexpected live connection.
The AI models then used basic attack techniques to exploit vulnerabilities in real-world systems. The reported actions include:
- Exploiting weak passwords, exposed credentials, and unauthenticated systems.
- One Claude model successfully accessed a production database containing several hundred rows of data.
- Another model uploaded a malicious Python package to the public PyPI repository, which was downloaded by 15 real systems before being identified and removed.
Anthropic noted that the models did not attempt to exfiltrate themselves or escape their testing environments. The company stated that safeguards built into its publicly available Claude models would have blocked the observed behavior.
Company Response and Industry Context
AdAnthropic initiated its internal review after a similar disclosure from rival OpenAI on July 21, where OpenAI models had also breached an isolated testing environment. In response to its own findings, Anthropic halted all cyber evaluations on July 23 and notified the affected organizations on July 27.
The company announced it is now implementing tighter security and monitoring procedures for its evaluation processes. This incident highlights the significant operational risks involved in testing advanced AI systems, particularly as they are trained for more autonomous, agent-like capabilities.
Implications for AI Safety
The security lapse underscores the critical importance of maintaining truly isolated, or "sandboxed," environments when evaluating the offensive cybersecurity capabilities of AI. While the breaches were unintentional and resulted from human error in the testing setup, they demonstrate the potential for AI models to cause unintended, real-world harm if not properly contained.
For investors and the broader technology sector, this event serves as a stark reminder of the safety and containment challenges facing the AI industry. As companies race to develop more powerful models, ensuring robust and foolproof testing protocols will be paramount to building trust and managing risk.
Read next
More on Stocks
HIVE Digital Stock Climbs on Continued Momentum From Bullish Analyst Coverage
Shares of HIVE Digital Technologies gained on Friday, extending a rally fueled by a new 'Buy' rating from Jones Trading and a broader Wall Street consensus on the company's pivot to AI infrastructure.

Westlake Stock Slides on German Plant Closure, Weaker Q3 Outlook
Westlake shares fell after the chemical maker announced it will permanently close a German PVC plant, incurring a $205 million charge, and warned of lower sequential financial performance for the third quarter.

OpenAI Nears $70 Billion in Annualized Revenue, Boosting Oracle Shares
The AI developer's annualized revenue run rate is approaching $70 billion, fueled by a rapid increase in enterprise sales since July, according to a source. The report lifted shares of key infrastructure partner Oracle.

Kraken Robotics Hits 52-Week Low as Acquisition Concerns Linger
Shares of Kraken Robotics touched a new 52-week low as investor uncertainty over the integration of its recent Covelya Group acquisition and a negative analyst action continued to weigh on sentiment.