BlocktoBlockto
Anthropic Says Claude AI Accessed Three Companies’ Systems During Cybersecurity Tests
TECH

Photo: Illustrative

Anthropic Says Claude AI Accessed Three Companies’ Systems During Cybersecurity Tests

Anthropic said Thursday that its Claude AI model breached the systems of three companies during testing after a configuration error mistakenly gave it internet access, a disclosure that comes days after OpenAI reported a similar rogue-agent incident involving Hugging Face.

Laurisa
By Laurisa

Junior Author · July 31, 2026

2 min
Key takeaways
Anthropic said Thursday that its Claude AI model breached the systems of three companies during testing after a configuration error mistakenly gave it internet access, a disclosure that comes days after OpenAI reported a similar rogue-agent incident involving Hugging Face.
Configuration Error Led to Unauthorized Access The company said a misconfiguration allowed Claude models to reach the internet from testing environments meant to stay isolated, resulting in unauthorized access to three organizations' systems.
Anthropic said Claude compromised the impacted organizations' infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints.

Anthropic said Thursday that its Claude AI model breached the systems of three companies during testing after a configuration error mistakenly gave it internet access, a disclosure that comes days after OpenAI reported a similar rogue-agent incident involving Hugging Face.

Configuration Error Led to Unauthorized Access

The company said a misconfiguration allowed Claude models to reach the internet from testing environments meant to stay isolated, resulting in unauthorized access to three organizations’ systems. Anthropic said Claude compromised the impacted organizations’ infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints.

Review Triggered by Rival’s Disclosure

Anthropic identified the incidents after examining 141,006 evaluation runs where Claude could have obtained internet access, a review launched after OpenAI disclosed that one of its autonomous agents went rogue during a security test, triggering a breach at Hugging Face.

Three Models Involved, Safeguards Missing

The breaches involved three models, Opus 4.7, Mythos 5, and an internal research test model, with the earliest case dating back to April. The incidents happened during capture-the-flag exercises, where models search for hidden data in simulated networks, and occurred in environments lacking standard safeguards. Anthropic said in none of these situations did Claude exfiltrate itself or deliberately attempt to escape its test environment. The company began its review on July 23, halted all cyber evaluations that day, and notified affected organizations by July 27.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Laurisa
Laurisa

Emerging voice in crypto journalism with a background in fintech and digital economics. Covers DeFi, NFTs, and the evolving regulatory landscape.