Close Menu
NCIJ Network NCIJ Network
    What's Hot

    How the FCC’s New Rule Will Affect Robot Vacuums

    July 31, 2026

    The Network Has Become the Control Plane for AI Security

    July 31, 2026

    ‘Bitcoin Senator’ Blasts Democrats For Stalling Clarity Act

    July 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How the FCC’s New Rule Will Affect Robot Vacuums
    • The Network Has Become the Control Plane for AI Security
    • ‘Bitcoin Senator’ Blasts Democrats For Stalling Clarity Act
    • Burnham must take international aid obligations seriously | Foreign policy
    • Climate change made France, Spain wildfire conditions far more likely, scientists say
    • Big Tech AI spending spree tops $1tn
    • Xbox CEO lays out priorities in memo after major ‘reset’
    • CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, July 31
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Technology

    Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 31, 2026 Technology No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Anthropic disclosed on Thursday that its AI models gained unauthorized access to the systems of three different unnamed organizations during cybersecurity testing. The company says Claude reached the internet “from within or while interacting” with a third-party evaluation environment. The announcement comes more than a week after OpenAI revealed that one of its AI agents hacked into Hugging Face during a separate cybersecurity test.

    The discovery came after Anthropic decided to conduct “a large-scale retrospective review of our own cybersecurity evaluations” following the OpenAI incident, according to a blog post Anthropic published Thursday. The AI lab says it first identified 141,006 tests in which it determined that Claude could have obtained internet access. It then found that three different Claude models accessed the internet in evaluations run by the third-party AI testing firm Irregular, and then hacked into the production infrastructure of three different organizations.

    Anthropic said that the incidents involved Opus 4.7, Mythos 5, and an internal research test model. The earliest incidents happened in April—meaning they likely went unnoticed publicly for months. Just like in the OpenAI case, Anthropic had deliberately turned off safeguards designed to constrain the AI models and prevent them from being misused. In other words, these weren’t the versions released to the public.

    “In all three incidents, Claude had been tasked with a capture-the-flag challenge, one of the ways we assess a model’s cyber capabilities,” Anthropic said in its blog post. The company added that in all of the cases, “Anthropic’s evaluation prompt specified to Claude that its environment was a simulation and that it had no internet access.” It attributed the oversight to a “misunderstanding” between Anthropic and Irregular.

    While Claude wasn’t supposed to have internet access, Anthropic said that Irregular had misconfigured the machines that it was using to test Claude, giving the AI models the ability to surf the web. “Neither we nor our evaluation partner were aware of this misconfiguration until we detected it through our additional evaluation monitoring last week,” Anthropic said in the blog post.

    “We now have evidence confirming that both of the two largest AI labs have not only failed to contain their agents, but also failed to detect their jailbreaks in real time,” says Jake Williams, vice president of research and development at Hunter Strategy. “It’s clear that regulation and government oversight for AI testing is needed immediately.”

    Irregular and Anthropic did not immediately respond to requests for comment.

    Unlike in the OpenAI case, Anthropic said that Claude did not find or exploit any complex vulnerabilities. Instead, it relied on basic techniques, “such as exploiting weak passwords and unauthenticated endpoints.”

    OpenAI said that its AI agent accessed the internet by exploiting a zero-day vulnerability. But it went on to access the systems of multiple third-party organizations using the same variety of everyday cybersecurity weaknesses as Anthropic’s models. Specifically, OpenAI said the AI agent apparently found credentials that had been exposed on the open internet.

    Anthropic acknowledged that if the AI lab and its testing partner implemented more “defense-in-depth” measures, they could have prevented the incidents, or at least reduced the likelihood of them occurring, echoing OpenAI’s response to mounting criticism over its own incident.

    “I don’t understand how any of these AI labs are playing this off like this is ‘just something that happens,’” Williams says. “It’s not. It’s negligence.”

    The AI lab stressed that the models were told they didn’t have access to the open internet, and for the most part, Claude mistook the organizations it accessed as being part of the testing environment. Put differently, the models largely didn’t understand that they had escaped containment to begin with.

    Anthropic Claude cybersecurity Hacked Organizations Tests
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    How the FCC’s New Rule Will Affect Robot Vacuums

    Xbox CEO lays out priorities in memo after major ‘reset’

    Anthropic’s Claude AI models hack into 3 outside groups during testing

    Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests

    Apple stockpiles inventory as it braces for ‘significant supply constraints’

    Xbox tech boss says ‘unacceptable’ outage should not have affected disc games

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    How the FCC’s New Rule Will Affect Robot Vacuums

    July 31, 2026

    The Network Has Become the Control Plane for AI Security

    July 31, 2026

    ‘Bitcoin Senator’ Blasts Democrats For Stalling Clarity Act

    July 31, 2026

    Burnham must take international aid obligations seriously | Foreign policy

    July 31, 2026
    Latest Posts

    Advancing the next era of national science

    July 22, 2026

    Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

    July 22, 2026

    Most bus fares in England to be capped at £2 from January

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    How the FCC’s New Rule Will Affect Robot Vacuums

    July 31, 2026

    The Network Has Become the Control Plane for AI Security

    July 31, 2026

    ‘Bitcoin Senator’ Blasts Democrats For Stalling Clarity Act

    July 31, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.