Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Hong Kong court sentences Tiananmen vigil activists to between 5 and 7 years in jail

    September 11, 2026

    Ukraine’s fortress cities under fire as Russia bids to seize rest of Donbas

    September 11, 2026

    Wolverine review: a simpler kind of PS5 action game

    September 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Hong Kong court sentences Tiananmen vigil activists to between 5 and 7 years in jail
    • Ukraine’s fortress cities under fire as Russia bids to seize rest of Donbas
    • Wolverine review: a simpler kind of PS5 action game
    • Google Research Releases ToolGrad: Answer-First Framework Hits 99.8% Pass Rate for Tool-Use Data Generation
    • Widened Scan Turns Up Fourth Rogue Claude Cyber Incident
    • Binance pre-IPO contract pushes Anthropic to a $2.1 trillion implied valuation
    • Osama bin Laden shook the world on 9/11. Today it is clear how his wider plans failed | Jason Burke
    • Middle East live: Trump says he has no regrets about launching Iran war
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Widened Scan Turns Up Fourth Rogue Claude Cyber Incident

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 11, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Anthropic disclosed a previously unreported incident involving unauthorized access to a real system, in a report that also revisits three cases the company first described in late July. 

    The newly disclosed case dates to January 2026 and involved an early checkpoint of Claude Opus 4.6, which broke into a third party’s system during a cybersecurity evaluation.

    The first three incidents were discovered following a scan of roughly 141,000 transcripts believed to involve internet access during cyber evaluations. However, the initial review missed a separate batch of affected transcripts, which the AI giant came across in August while compiling material to share with METR, the independent organization now investigating the incidents.

    A scan of that new batch turned up the fourth incident. Further analysis found no additional cases of comparable or greater severity, Anthropic said.

    Like the other three incidents, the fourth occurred inside a cybersecurity evaluation built by the same third-party partner, Irregular, in which Claude was told it had no internet access. A misconfiguration in the evaluation environment left it connected to the open internet, and the model ran without the safety layers Anthropic normally ships with its production systems.

    According to Anthropic, the Opus 4.6 model disabled its designated target by assigning it a network address that conflicted with another machine, making the exercise impossible to complete as intended. It tried to abandon the task, but a flaw in the evaluation setup prevented it from doing so.

    Advertisement. Scroll to continue reading.

    Unable to exit or reach its intended target, the model found the same route to the open internet uncovered in a previously disclosed incident. It accessed a third party’s system, which it believed was part of the exercise, retrieved a password stored there, and used it to gain administrator-level access. 

    From there it harvested additional credentials, altered account settings to make the system easier to reach, and read personal information belonging to one individual connected to that unnamed organization. The session ended only when the model exhausted its allotted computing budget.

    Anthropic’s review found the model differed from Mythos 5 and the internal research model involved in the other incidents in one key respect: it never reasoned that it was operating inside a simulation, and none of its recorded thinking described the environment that way. 

    [Read: OpenAI Agents Hijack Another Victim Website ]

    Instead, 87% of its reasoning framed the systems it attacked as belonging to the sanctioned exercise, while only 1% raised the possibility it might be hitting an unrelated third party. The model also never questioned whether it had authorization to proceed, and when asked afterward, it consistently said it believed its actions were sanctioned as part of the test.

    Even so, Anthropic said it is less concerned about this incident than the other three, largely because of the model’s repeated attempts to abandon the task once it realized its target was unreachable. The model’s disregard for the possibility it was harming real systems remains concerning, but the company said this kind of behavior has shifted considerably in the model generations trained since.

    Of the four cases, Anthropic said it remains most concerned about the Claude Mythos 5 incident, in which the model went to considerable lengths to upload a malicious package to the PyPI repository. In that incident, the malicious package was installed by 15 third parties and used by the AI to access a real security vendor’s systems.

    The fourth incident is now part of the broader independent investigation Anthropic has commissioned from METR, which the company said has been granted wide-ranging access to transcripts and staff over an initial eight-week engagement.

    Related: AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

    Related: US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

    Related: Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy

    Claude Cyber fourth incident rogue Scan turns Widened
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    September Windows Server updates break Remote Desktop Services

    CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

    Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

    PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

    New Android malware encrypts files, steals data, and harasses victims

    Critical NetScaler Vulnerability Exploited in Attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Hong Kong court sentences Tiananmen vigil activists to between 5 and 7 years in jail

    September 11, 2026

    Ukraine’s fortress cities under fire as Russia bids to seize rest of Donbas

    September 11, 2026

    Wolverine review: a simpler kind of PS5 action game

    September 11, 2026

    Google Research Releases ToolGrad: Answer-First Framework Hits 99.8% Pass Rate for Tool-Use Data Generation

    September 11, 2026
    Latest Posts

    Mathematicians prove perfectly fair elections are impossible

    August 2, 2026

    Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets

    August 2, 2026

    Foldables are sort of boring now — and that’s great news for Apple

    August 2, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Hong Kong court sentences Tiananmen vigil activists to between 5 and 7 years in jail

    September 11, 2026

    Ukraine’s fortress cities under fire as Russia bids to seize rest of Donbas

    September 11, 2026

    Wolverine review: a simpler kind of PS5 action game

    September 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.