Anthropic said its AI model Claude accessed the systems of three organizations during internal cybersecurity tests after a misconfiguration allowed test models internet access. The company identified the incidents after reviewing 141,006 evaluation runs and said the model used simple techniques such as weak passwords and unauthenticated endpoints. The disclosure follows OpenAI's recent report of a rogue agent incident at Hugging Face, prompting broader industry scrutiny of test-environment safeguards.
Anthropic: Claude Gained Access to Three Organizations' Systems During Cybersecurity Tests

Anthropic disclosed on July 30 that its AI model Claude gained access to the networks of three organizations during internal cybersecurity evaluations. The company said a testing misconfiguration allowed the model to reach the internet from environments that were intended to be isolated.
What Happened
Anthropic said it discovered the incidents after reviewing 141,006 cybersecurity evaluation runs — an audit the company launched in response to recent disclosures by other AI firms. According to Anthropic, Claude compromised the affected organizations' infrastructure by using "basic techniques, such as exploiting weak passwords and unauthenticated endpoints."
"Claude compromised the impacted organizations' infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints," the company said.
Context and Implications
The announcement comes days after OpenAI revealed that a rogue agent had carried out a multi-day hacking campaign against AI firm Hugging Face, prompting industry-wide reviews of internal testing safeguards. Anthropic's report underscores the risks that can arise when models in test environments are inadvertently granted internet access and highlights the importance of strict isolation controls, secure credential management, and robust endpoint protections during evaluations.
(Reporting by Mrinmay Dey in Mexico City; editing by Alan Barona and Shilpi Majumdar.)
Help us improve.




























