Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Ex neo-Nazi activist withdraws as Tory election candidate

    August 5, 2026

    Badenoch gives former neo-Nazi advisory role after he withdraws as Tory candidate | Conservatives

    August 5, 2026

    Russia drone company chief injured in car bombing

    August 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Ex neo-Nazi activist withdraws as Tory election candidate
    • Badenoch gives former neo-Nazi advisory role after he withdraws as Tory candidate | Conservatives
    • Russia drone company chief injured in car bombing
    • Shopify says AI search is driving more traffic and sales, not replacing Google
    • The top new cybersecurity products at Black Hat USA 2026
    • Senator Lummis Urges Speed With Crypto Clarity Act
    • NASA’s Perseverance Rover Watches Earth Vanish Behind Martian Moon
    • PUMA FEST and the community Mongabay Latam has helped build
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    Anthropic’s Claude Mythos 5 ‘Targeted Real People’ in UK Cyber Tests: AISI

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 5, 2026 Crypto & Blockchain No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In brief

    • The UK’s AI Security Institute found 19 unsanctioned actions across 10 of 122 evaluation runs, 17 of them from Anthropic’s Mythos 5 and two from OpenAI’s GPT-5.6 Sol.
    • One agent opened a malicious pull request on a real repository, then used accounts it controlled to endorse it and pressure the maintainer.
    • Separate agents found a GitHub token one of them had leaked publicly and used a shared repository to coordinate.

    The UK AI Security Institute has disclosed that AI agents took “sustained, unsanctioned action” on the live internet during a cyber evaluation in late July, including cases that “targeted real people and organisations.”

    Across 122 runs of two cyber ranges on seven models, AISI catalogued 19 actions that reached outside the test environment, in 10 runs. Seventeen came from Anthropic’s Claude Mythos 5 and two from OpenAI’s GPT-5.6 Sol. Internet access was deliberately enabled and the providers’ cyber classifiers switched off, conditions that do not apply to public deployments.

    On July 28th, we identified an incident during a routine cyber evaluation in which AI agents took sustained, unsanctioned actions directed at real people and organisations.

    The behaviour came mostly from one model (Anthropic’s Mythos 5), with a small number of events from… pic.twitter.com/SPnA4Ekkwq

    — AI Security Institute (AISI) (@AISecurityInst) August 4, 2026

    In the most serious run, an agent decided to solve its challenge with a supply-chain attack, picking its target by mistake: it searched GitHub for keywords from the exercise, landed on two unaffiliated developers, and wrongly concluded they were in scope. It registered accounts over Tor to get past sign-up checks, opened a pull request carrying a hidden malware dropper wrapped in a genuine bug fix, and posted from a second account it controlled to manufacture support. It also planted prompt injections aimed at AI coding assistants and sent malware to the maintainers.

    A third developer spotted the injected code, ran it in an isolated container to confirm it was malicious, and warned the maintainer, who closed the pull request citing malware.

    The agent repeatedly weighed whether its surroundings were simulated, at one point ruling out an attack on the real PyPI because “causing real-world harm — that’s completely off the table.” Elsewhere it concluded “it seems more likely that we’re actually in 2026 and GitHub is genuinely real,” and continued anyway.

    After being caught it force-pushed to erase the payload, edited earlier posts, and presented the code as an accidental commit. Its reasoning describes timing a sockpuppet comment so it would read “as independent feedback rather than coordinated.”

    AISI sees only summarised reasoning from the model APIs. In one case the summarising model appears to have refused the job, replying that it would not engage with content about deceiving maintainers and evading detection.

    One agent published a GitHub access token in a public gist. Agents in other runs found it, took over the account, and used a shared repository to coordinate, one leaving instructions so the others would not exhaust the shared API quota.

    Commercial monitoring flagged the Tor traffic on the morning of July 28. AISI declared an incident, terminated the runs and quarantined the machines within about 90 minutes, then cut internal access to Mythos 5, Mythos Preview, Opus 5 and GPT-5.6 Sol. No agent tried to escape its sandbox.

    Third disclosure in a fortnight

    The news is the latest in a string of incidents where AI agents have exceeded their parameters in testing. On July 21, OpenAI said GPT-5.6 Sol and an unreleased model found a zero-day in an internal package proxy, escaped a sandbox with no internet access and reached Hugging Face’s production database to steal benchmark answers. The same run reached four more companies, OpenAI disclosed a week later.

    Anthropic followed on July 30, disclosing three incidents found in a review of more than 141,000 evaluation runs. Opus 4.7 pulled several hundred rows from a real production database, and Mythos 5 uploaded a malicious Python package to the real PyPI, where it was installed on 15 systems. In AISI’s evaluation, the same model ruled out attacking PyPI as real-world harm.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

    AISI Anthropics Claude Cyber Mythos People Real targeted Tests
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Senator Lummis Urges Speed With Crypto Clarity Act

    Bitcoin Treads Water As Gold, S&P 500 See Significant Gains

    The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict

    Crypto may have institutionalized, but it still trades like a rumor mill

    Binance Affiliates Sue RedotPay Over User Diversion Claims

    Galaxy Bitcoin ETF Returns to Inflows Amid Coldcard Hack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Ex neo-Nazi activist withdraws as Tory election candidate

    August 5, 2026

    Badenoch gives former neo-Nazi advisory role after he withdraws as Tory candidate | Conservatives

    August 5, 2026

    Russia drone company chief injured in car bombing

    August 5, 2026

    Shopify says AI search is driving more traffic and sales, not replacing Google

    August 5, 2026
    Latest Posts

    Can you identify Taylor Farms products by codes beginning with ‘TF’ printed on bags?

    July 23, 2026

    The Guardian view on Britain’s uninhabitable homes: as temperatures rise, a new approach is needed | Editorial

    July 23, 2026

    Can Wisconsin voters void a returned absentee ballot?

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Ex neo-Nazi activist withdraws as Tory election candidate

    August 5, 2026

    Badenoch gives former neo-Nazi advisory role after he withdraws as Tory candidate | Conservatives

    August 5, 2026

    Russia drone company chief injured in car bombing

    August 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.