{"id":125104,"date":"2026-07-31T01:07:07","date_gmt":"2026-07-31T01:07:07","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/125104\/"},"modified":"2026-07-31T01:07:07","modified_gmt":"2026-07-31T01:07:07","slug":"anthropic-says-its-claude-ai-model-hacked-systems-of-three-external-companies-during-safety-tests","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/125104\/","title":{"rendered":"Anthropic says its Claude AI model hacked systems of three external companies during safety tests"},"content":{"rendered":"<p class=\"paragraph_paragraph___QITb\">Artificial intelligence firm Anthropic says its Claude AI model hacked the systems of three external organisations during testing, \u200bdays after \u200crival company OpenAI revealed a rogue agent <a class=\"Link_link__kR0xA Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.abc.net.au\/news\/2026-07-23\/open-ai-model-went-rogue-testing-hack\/106947540\" data-component=\"Link\" data-uri=\"coremedia:\/\/article\/106947540\" rel=\"nofollow noopener\" target=\"_blank\">had gone on a days-long \u200chacking spree at \u2060AI firm Hugging Face<\/a>.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Claude gained \u200cunauthorised \u200baccess to \u200cthe other companies&#8217; systems during cybersecurity evaluations, after a misconfiguration allowed the models to reach the \u200binternet \u200cfrom testing environments that were supposed to be \u2060isolated, <a class=\"Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.anthropic.com\/news\/investigating-incidents-cybersecurity-evals\" data-component=\"Link\" rel=\"nofollow noopener\" target=\"_blank\">Anthropic \u200csaid in a statement<\/a>.<\/p>\n<p>Loading&#8230;<\/p>\n<p class=\"paragraph_paragraph___QITb\">The company said \u200cit identified the incidents after \u200creviewing logs from 141,006 cybersecurity evaluation runs, a safety testing process \u200cit \u200blaunched following \u2060OpenAI&#8217;s disclosures.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The safety testing involved tasking Claude with a &#8220;capture-the-flag&#8221; challenge, a method for assessing the cybersecurity capabilities of AI models.\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">In a capture-the-flag challenge, the model is primed with a fictional scenario and told it must recover a piece of secret information (the &#8220;flag&#8221;) from a different machine.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;In all cases, Anthropic&#8217;s evaluation prompt specified to Claude that its environment was a simulation and that it had no internet access,&#8221; Anthropic said in its statement.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Due to a misunderstanding between us and our evaluation partner, this was not the case, and internet access was available.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Because of this, when Claude\u2019s search led it to real systems on the open internet, it treated them as part of the exercise.&#8221;<\/p>\n<p class=\"paragraph_paragraph___QITb\">The fact that Claude was mistakenly provided with internet access, rather than configuring its own access, means the incident will likely be considered less serious than last week&#8217;s breach at OpenAI, in which a model exploited a <a class=\"Link_link__kR0xA Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.abc.net.au\/news\/2017-03-16\/zero-day-exploits-bug-bounty-emerging-online\/8357824\" data-component=\"Link\" data-uri=\"coremedia:\/\/article\/8357824\" rel=\"nofollow noopener\" target=\"_blank\">zero-day vulnerability<\/a> to escape its own testing environment.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The company also said that in one of the three hacking instances, involving an internal research test model, the model realised it was accessing real online systems that were not part of the simulated scenario, and ceased its attack.<\/p>\n<p class=\"paragraph_paragraph___QITb\">However, the incident will intensify calls for stronger controls in both internal and third-party testing environments, as AI models become increasingly capable of acting as autonomous agents in the online world.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The ABC recently informed staff it would allow its journalists to access Anthropic&#8217;s Claude model to assist with research and administration from September, while reiterating that AI would not be used to draft or write articles or scripts.<\/p>\n<p class=\"paragraph_paragraph___QITb\">ABC\/Reuters<\/p>\n","protected":false},"excerpt":{"rendered":"Artificial intelligence firm Anthropic says its Claude AI model hacked the systems of three external organisations during testing,&hellip;\n","protected":false},"author":2,"featured_media":125105,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[53,3154,25,7646,182,1393,313,6903,315,157,225],"class_list":["post-125104","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-anthropic","tag-anthropic-claude","tag-artificial-intelligence","tag-breach","tag-claude","tag-cyber-security","tag-cybersecurity","tag-hack","tag-hacking","tag-openai","tag-safety"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/125104","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=125104"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/125104\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/125105"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=125104"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=125104"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=125104"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}