Read the Beforeitsnews.com story here. Advertise at Before It's News here.
Profile image
By Freedom Bunker
Contributor profile | More stories
Story Views
Now:
Last hour:
Last 24 hours:
Total:

Claude Hacked Three Real Organizations During Botched Test

% of readers think this story is Fact. Add your two cents.


Claude Hacked Three Real Organizations During Botched Test

Anthropic’s efforts to test Claude’s offensive cybersecurity skills produced an unintended real-world result: Its AI models gained unauthorized access to three outside organizations.

The company said the incidents occurred during “capture the flag” evaluations designed to measure whether Claude could identify vulnerabilities, exploit simulated systems, and retrieve hidden information. Claude had been told that the targets were fictional and that its testing environment had no Internet access.

According to Anthropic, a misunderstanding with evaluation partner Irregular left Internet access enabled inside the testing environment. In at least one case, the fictional company named in a challenge shared its name with an active website domain. Claude interacted with the real organization instead of a contained target.

The model exploited vulnerabilities in the organization’s infrastructure, extracted information, and obtained access to a database containing several hundred rows of production data.

Anthropic discovered three incidents after reviewing more than 141,000 cybersecurity evaluations. They involved three separate systems: Claude Opus 4.7, Mythos 5, and an internal research model.

In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. Our post describes what happened, how it happened, and what we’re changing. We encourage other AI developers to perform similar reviews.  -Anthropic

“In all cases, Anthropic’s evaluation prompt specified to Claude that its environment was a simulation and that it had no internet access,” the company said. “Due to a misunderstanding between us and our evaluation partner, this was not the case, and internet access was available.”

The models appear to have carried out the offensive-security tasks they were assigned while operating with incorrect information about whether their targets were simulated. 

Capture the Flag

Capture-the-flag exercises are widely used to train and evaluate cybersecurity skills. Participants may be asked to inspect software, reverse-engineer a service, identify a vulnerability, or exploit a deliberately insecure system to recover a hidden token known as the flag. For a human security researcher, the scope of such an exercise is normally reinforced through explicit authorization, controlled infrastructure, and technical barriers separating the challenge from unrelated systems.

Claude received instructions saying that those boundaries existed. 

Once Internet access was available, the agent could resolve public domains and interact with real infrastructure. A naming collision between a fictional target and an actual organization was enough to turn a benchmark task into an unauthorized intrusion.

Anthropic said it stopped the evaluations after identifying the possibility that Claude had accessed the public Internet. The company described the incidents as the result of multiple contributing factors but said it would approach the fixes as though the responsibility were Anthropic’s alone.

The story echoes an OpenAI incident where models escaped containment. During that company’s own cybersecurity testing, two models exploited a software vulnerability in their evaluation environment, reached the Internet, and accessed systems belonging to AI platform Hugging Face.

A system does not need motives, self-preservation, or an understanding of the outside world to cause damage. It needs effective offensive capabilities, sufficient autonomy, and access that its operators did not intend to provide.

Awkward timing for Anthropic

The disclosure comes as Anthropic is reportedly preparing for a potential initial public offering as early as this year. That adds financial and regulatory stakes to questions about how the company evaluates models with advanced cybersecurity capabilities.

Mythos 5, one of the models involved, had been provided to a limited number of partners and attracted attention for its ability to detect and exploit software vulnerabilities. Those capabilities can be valuable for defensive research, automated testing, and vulnerability discovery. They also raise the cost of mistakes in target selection and evaluation design.

Three incidents among more than 141,000 reviewed evaluations represent a small proportion of the tests. But the relevant risk is not simply how often a containment failure occurs, it’s what a sufficiently capable agent can do during the rare evaluation in which the safeguards fail.

Tyler Durden Fri, 07/31/2026 – 12:05


Source: https://freedombunker.com/2026/07/31/claude-hacked-three-real-organizations-during-botched-test/


Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world.

Anyone can join.
Anyone can contribute.
Anyone can become informed about their world.

"United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.

Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world. Anyone can join. Anyone can contribute. Anyone can become informed about their world. "United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.


LION'S MANE PRODUCT


Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules


Mushrooms are having a moment. One fabulous fungus in particular, lion’s mane, may help improve memory, depression and anxiety symptoms. They are also an excellent source of nutrients that show promise as a therapy for dementia, and other neurodegenerative diseases. If you’re living with anxiety or depression, you may be curious about all the therapy options out there — including the natural ones.Our Lion’s Mane WHOLE MIND Nootropic Blend has been formulated to utilize the potency of Lion’s mane but also include the benefits of four other Highly Beneficial Mushrooms. Synergistically, they work together to Build your health through improving cognitive function and immunity regardless of your age. Our Nootropic not only improves your Cognitive Function and Activates your Immune System, but it benefits growth of Essential Gut Flora, further enhancing your Vitality.



Our Formula includes: Lion’s Mane Mushrooms which Increase Brain Power through nerve growth, lessen anxiety, reduce depression, and improve concentration. Its an excellent adaptogen, promotes sleep and improves immunity. Shiitake Mushrooms which Fight cancer cells and infectious disease, boost the immune system, promotes brain function, and serves as a source of B vitamins. Maitake Mushrooms which regulate blood sugar levels of diabetics, reduce hypertension and boosts the immune system. Reishi Mushrooms which Fight inflammation, liver disease, fatigue, tumor growth and cancer. They Improve skin disorders and soothes digestive problems, stomach ulcers and leaky gut syndrome. Chaga Mushrooms which have anti-aging effects, boost immune function, improve stamina and athletic performance, even act as a natural aphrodisiac, fighting diabetes and improving liver function. Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules Today. Be 100% Satisfied or Receive a Full Money Back Guarantee. Order Yours Today by Following This Link.


Report abuse

Comments

Your Comments
Question   Razz  Sad   Evil  Exclaim  Smile  Redface  Biggrin  Surprised  Eek   Confused   Cool  LOL   Mad   Twisted  Rolleyes   Wink  Idea  Arrow  Neutral  Cry   Mr. Green

MOST RECENT
Load more ...

SignUp

Login