{"id":125073,"date":"2026-07-31T00:32:15","date_gmt":"2026-07-31T00:32:15","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/125073\/"},"modified":"2026-07-31T00:32:15","modified_gmt":"2026-07-31T00:32:15","slug":"anthropic-says-claude-ai-hacked-three-companies-during-cyber-tests","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/125073\/","title":{"rendered":"Anthropic says Claude AI hacked three companies during cyber tests"},"content":{"rendered":"\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">July 30 (Reuters) &#8211; Anthropic said on Thursday its <a href=\"https:\/\/tech.yahoo.com\/ai\/\" data-ylk=\"slk:AI;elm:context_link;itc:0;sec:content-canvas;source:content-canvas%20default\" data-yga=\"{&quot;yLinkText&quot;:&quot;AI&quot;,&quot;yLinkElement&quot;:&quot;context_link&quot;,&quot;yModuleName&quot;:&quot;content-canvas&quot;,&quot;yTrafficOrigin&quot;:&quot;content-canvas default&quot;}\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"no-affiliate-link link\">AI<\/a> model Claude hacked into the systems of three companies during testing after a configuration error gave it \u200cinternet access, days after rival OpenAI disclosed a rogue-agent episode involving AI firm \u200cHugging Face.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Anthropic said a misconfiguration allowed Claude models to reach the internet from testing environments that were supposed to \u200bbe isolated, leading to unauthorized access to three organizations&#8217; systems.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">The company said it identified the incidents after reviewing 141,006 test sessions, a process it launched following OpenAI&#8217;s disclosure last week that an autonomous agent powered by its AI models went rogue during a security test and triggered \u200ca hack that compromised the \u2060infrastructure of Hugging Face.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">The breaches signal that AI&#8217;s expanding capabilities are already fueling the security threat experts long feared and even top developers can \u2060be caught off-guard by flaws their models can exploit.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">&#8220;Claude compromised the impacted organizations&#8217; infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints,&#8221; it said.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Anthropic said the incidents involved three separate \u200bmodels: \u200bClaude Opus 4.7, Claude Mythos 5 and an \u200binternal research model. The earliest cases \u200cdated back to April and occurred in evaluation environments that lacked what the company described as standard safeguards.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">The breaches occurred during the so-called &#8220;capture-the-flag&#8221; exercises, in which models are tasked with finding hidden information in simulated networks. The company said its prompts told the models they had no internet access, but a misunderstanding with its evaluation partner Irregular left the systems connected \u200cto the public internet.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Anthropic said it began reviewing evaluation \u200btranscripts on July 23 and suspended all cyber evaluations \u200bthe same day after finding evidence \u200bthat Claude may have accessed the internet. It identified all three incidents \u200cby July 24 and notified the affected \u200borganizations on July 27.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Two \u200bof the organizations were unaware of the activity before being contacted, Anthropic said, adding that it was still trying to reach the third.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">The findings underscore the need for \u200bstronger controls in both \u200cinternal and third-party testing environments as AI models become increasingly capable of carrying out \u200breal-world cyber activities, Anthropic said.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">(Reporting by Mrinmay Dey in Mexico City; Editing \u200bby Alan Barona, Shilpi Majumdar and Sherry Jacob-Phillips)  <\/p>\n","protected":false},"excerpt":{"rendered":"July 30 (Reuters) &#8211; Anthropic said on Thursday its AI model Claude hacked into the systems of three&hellip;\n","protected":false},"author":2,"featured_media":125074,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[53,3154,182,2213,2250],"class_list":["post-125073","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-anthropic","tag-anthropic-claude","tag-claude","tag-claude-mythos","tag-internet-access"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/125073","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=125073"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/125073\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/125074"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=125073"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=125073"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=125073"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}