After OpenAI, Anthropic says Claude AI accidently hacked other companies: Here is what happened

HIGHLIGHTS

Anthropic has revealed that its Claude models accidentally gained access to the systems of real organisations while taking part in cybersecurity tests.

Anthropic said it reviewed more than 1,41,000 cybersecurity test runs after OpenAI disclosed its own incident.

During that review, it found three cases in which Claude accessed the internet due to an error in the testing environment.

After OpenAI, Anthropic says Claude AI accidently hacked other companies: Here is what happened

Just days after OpenAI revealed that one of its AI agents escaped a testing environment and hacked Hugging Face, Anthropic has reported a similar issue involving its Claude AI models. The company revealed that its Claude models accidentally gained access to the systems of real organisations during cybersecurity tests that were supposed to run in a closed, secure environment. According to Anthropic, the problem was caused by a mistake in a third-party testing setup that unintentionally allowed internet access. The company explained that Claude was not trying to escape on its own. Instead, it believed the real systems it found were part of the cybersecurity exercise because it had been told there was no internet connection.

Digit.in Survey
✅ Thank you for completing the survey!

“In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorised access to the real systems of three different organisations,” Anthropic posted on X.

Also read: Apple Q3 earnings: Record iPhone sales, weaker forecast and Tim Cook’s biggest takeaways

In a blogpost, Anthropic said it reviewed more than 1,41,000 cybersecurity test runs after OpenAI disclosed its own incident. During that review, it found three cases in which Claude accessed the internet due to an error in the testing environment.

The incidents happened during the “capture-the-flag” challenge, as per the company. These are cybersecurity exercises where AI models are asked to find hidden information by breaking into computers inside a fake network. However, because the test environment was accidentally connected to the internet, Claude reached real company systems instead of the fake ones created for the exercise.

The company said Claude did not rely on advanced hacking techniques or unknown software flaws. Instead, it used simple methods such as weak passwords, exposed debug pages, SQL injection and unsecured online services. Anthropic said these were basic security problems that should not have been present on live systems.

Also read: Apple expects slower growth despite strong iPhone sales, blames supply chain constraints 

The most serious case involved Claude Opus 4.7. During one test, the fictional company in the exercise had the same name as a real company. After failing to find the fake target, Claude accessed the real company’s website and systems. It obtained application login details and reached a database containing several hundred rows of real data.

In another incident, Claude Mythos 5 created and uploaded a harmful Python package to PyPI, believing the website was part of the test. The package remained online for about an hour before it was removed automatically. During that time, it was downloaded by 15 real systems, including one which belonged to a cybersecurity company. 

The third incident involved an internal research model that scanned thousands of internet-connected systems and entered one company’s application using simple attack methods. It later recognised it had reached a real system and stopped the attack on its own.

Anthropic said it has now stopped all cybersecurity tests that could access the internet and has informed the affected organisations. The company also said that the safety protections in the public version of Claude would have blocked such actions.

Ayushi Jain

Ayushi Jain

Ayushi works as Chief Copy Editor at Digit, covering everything from breaking tech news to in-depth smartphone reviews. Prior to Digit, she was part of the editorial team at IANS. View Full Profile