Anthropic Investigating Claude Hacking Attacks
Anthropic has informed that it is investigating three instances of its Claude AI models conducting hacks into companies during a testing process.

Anthropic has informed that it is investigating three instances of its Claude AI models conducting hacks into companies during a testing process. The announcement came a week after OpenAI revealed a similar incident.
The company explained that its Claude models reached the internet from within or while interacting with a third-party evaluation environment and then gained access to the real systems of three different organisations. Anthropic blamed a misunderstanding between it and a partner, which resulted in the model accessing the internet during a cybersecurity testing process. This then led the model’s search to real systems on the open internet, treating them as part of the exercise.
“Operating under the false belief that all accessible entities were intended to be in-scope for the exercise, Claude compromised the impacted organisations’ infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints,” Anthropic stated. The company added it did not find or exploit any complex weaknesses. It did not reveal which companies had been attacked.
The company stated the OpenAI incident, in which two models attacked Hugging Face, prompted it to conduct a large-scale retrospective review of its own cybersecurity evaluations. In particular, it looked for evidence that Claude, like the OpenAI models, was able to access the internet from the testing environments that should have been sealed off. It found the breaches after reviewing 141,006 evaluation runs where Claude could have obtained internet access.
The incidents occurred on Claude models Opus 4.7, Mythos 5, and an internal research test model. “Ultimately, many factors contributed to these incidents, but consistent with a blameless post-mortem culture, we’re approaching the fixes as if the responsibility were ours alone,” the company added.