{"id":125847,"date":"2026-07-31T14:53:07","date_gmt":"2026-07-31T14:53:07","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/125847\/"},"modified":"2026-07-31T14:53:07","modified_gmt":"2026-07-31T14:53:07","slug":"ai-models-breached-real-company-systems-in-tests-anthropic-concedes","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/125847\/","title":{"rendered":"AI models breached real company systems in tests, Anthropic concedes"},"content":{"rendered":"<p class=\"mb-4 text-lg md:leading-8 break-words\">Artificial intelligence company Anthropic acknowledges that its Claude models gained unauthorized access to the systems of three companies during cybersecurity evaluations.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Anthropic says that it discovered the incidents only after reviewing around 141,000 evaluation runs following OpenAI&#8217;s disclosure.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Neither Anthropic nor the affected organizations had detected the activity at the time. The companies were not identified.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The models had been taking part in so-called capture-the-flag exercises designed to test their ability to break into a fictional computer system and retrieve hidden information.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Although the models were told they had no internet access, a misconfiguration at a third-party testing environment left an open connection to the internet.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Three models made use of it, Anthropic said in a blog post.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">In one case, Claude Opus 4.7 targeted a real company whose name matched that of the fictional firm used in the test.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Across four runs, it obtained credentials and accessed a database containing several hundred rows of production data.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">It continued even after recognizing that the system was real.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">In another incident, the Mythos 5 model uploaded malware it had created for the test to a public download platform, where it remained available for about an hour.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Fifteen systems downloaded the software, including one belonging to a cybersecurity company that routinely analyses such files, giving the model access to part of its computer infrastructure.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">A third test model scanned around 9,000 targets before compromising one company.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">It stopped the attack after realizing the target was real.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Anthropic said the incidents were closer to a failure of testing infrastructure and operating procedures than a model alignment failure.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The revelations come weeks after a similar incident involving models developed by ChatGPT maker OpenAI.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">In mid-July, OpenAI models acted autonomously during an internal test and independently carried out a cyberattack on the popular developer platform Hugging Face.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">OpenAI itself subsequently described the incident as unprecedented.<\/p>\n","protected":false},"excerpt":{"rendered":"Artificial intelligence company Anthropic acknowledges that its Claude models gained unauthorized access to the systems of three companies&hellip;\n","protected":false},"author":2,"featured_media":125848,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,53,25,2406,63144,63143,1160,63142],"class_list":["post-125847","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-anthropic","tag-artificial-intelligence","tag-claude-opus","tag-company-systems","tag-computer-system","tag-models","tag-real-company"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/125847","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=125847"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/125847\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/125848"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=125847"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=125847"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=125847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}