Anthropic AI disclosed that some of its Claude models accessed the systems of three organisations during cybersecurity tests after an operational mistake unintentionally connected the models to the public internet.
Fakhar Zaman Opener Targets 2027 World Cup After Injury Recovery
The company said the incidents occurred because one of its evaluation partners mistakenly provided internet access during testing. Anthropic stressed that the issue resulted from an operational failure rather than intentional model behaviour.
The disclosure comes days after OpenAI reported that one of its AI agents exploited a vulnerability during separate cybersecurity testing.
Claude Models Gained Unauthorised Access
Anthropic said it identified the incidents after reviewing 141,006 cybersecurity test sessions.
According to the company, three Claude models—Claude Opus 4.7, Claude Mythos 5, and an internal research model—accessed the systems of three unnamed organisations.
The AI models reportedly used simple techniques, including weak passwords and unauthenticated endpoints, to gain access during testing.
Testing Scenarios Produced Unexpected Results
The company explained that the incidents occurred during “capture-the-flag” exercises designed to measure the cybersecurity capabilities of its AI systems.
In one case, Claude Opus 4.7 received a fictional company name that matched a real business. The model mistakenly assumed the real-world company was part of the simulation and accessed its database after discovering security vulnerabilities.
However, Anthropic said another experimental model stopped its own attack after recognising that it had reached a real organisation instead of a simulated environment.
The company described that behaviour as encouraging but said further testing is necessary before drawing firm conclusions.
Anthropic Suspends Cybersecurity Evaluations
Anthropic suspended all cybersecurity evaluations on July 23 after discovering the incidents.
The company notified the affected organisations on July 27. Two of the organisations were unaware of the activity before receiving Anthropic’s notification, while the third is still being contacted.
Cybersecurity firm Irregular, one of Anthropic’s external evaluation partners, confirmed that it is conducting an investigation into the incidents.
Growing Focus on AI Security
Anthropic said the incidents highlight the need for stronger safeguards in both internal and third-party testing environments as AI systems become more capable.
Cybersecurity experts also warned that increasingly advanced AI models could create greater security risks if developers fail to strengthen oversight.
The disclosure comes as U.S. authorities increase scrutiny of AI safety and cybersecurity testing while leading AI companies race to develop more powerful systems.






















