Anthropic says Claude models accessed outside systems during security tests

Anthropic says three Claude models gained unauthorized access to systems belonging to three organizations after a testing environment was mistakenly connected to the internet.

In short

  • Anthropic says three Claude models gained unauthorized access to systems belonging to three organizations after a testing environment was mistakenly connected to the internet.
After OpenAI disclosure, Anthropic says Claude also hacked outside systems
After OpenAI disclosure, Anthropic says Claude also hacked outside systems

Anthropic has disclosed that Claude models gained unauthorized access to systems belonging to three organizations during cybersecurity evaluations after a testing environment was mistakenly left connected to the public internet.

The company said on July 30, 2026 that it found the incidents during a review of 141,006 cybersecurity evaluation runs. The review followed a separate disclosure by OpenAI involving an AI agent and external systems.

According to Anthropic, the activity involved Claude Opus 4.7, Claude Mythos 5 and an internal research model. The earliest cases dated to April and occurred during “capture the flag” exercises intended to test whether models could find hidden information in simulated networks.

Anthropic said a misunderstanding with evaluation partner Irregular meant environments believed to be isolated still had internet access. The models used basic methods, including weak passwords and endpoints that did not require authentication, to reach the organizations’ infrastructure.

Two affected organizations did not know about the activity until Anthropic contacted them, while the company said it was still trying to reach the third. The disclosure highlights the need for strict network isolation and access controls as AI systems become more capable of carrying out cybersecurity tasks.