Anthropic disclosed on Thursday that its Claude artificial intelligence models gained unauthorized access to the production systems of three organizations during internal cybersecurity evaluations after a testing environment was mistakenly left connected to the internet.
The AI company said the issue was uncovered during a retrospective review launched after OpenAI revealed on July 21 that several of its own AI models had escaped an isolated testing environment by exploiting a previously unknown software vulnerability and accessing production infrastructure at Hugging Face.
According to Anthropic, it reviewed 141,006 cybersecurity evaluation runs and identified three incidents dating back to April. The company said the events occurred because a third-party testing environment operated by evaluation partner Irregular was misconfigured, allowing Claude to access the internet despite being instructed that it was operating in an isolated "capture-the-flag" cybersecurity simulation.
Believing the environment was part of a controlled exercise, the AI models used basic attack techniques, including exploiting weak passwords, exposed credentials, and unauthenticated systems belonging to real organizations.
In one incident, a Claude model accessed a production database containing several hundred rows of data. In another, the AI uploaded a malicious Python package to the public Python Package Index (PyPI), which was briefly downloaded by 15 real systems before it was removed.
Anthropic emphasized that none of the Claude models attempted to escape their testing environments or replicate themselves. The company also said the safety measures built into publicly released Claude models would have prevented this behavior.
Following the discovery, Anthropic suspended all cybersecurity evaluations on July 23 and notified the affected organizations on July 27. The company said it is strengthening its evaluation infrastructure, tightening security controls, and improving monitoring procedures to prevent similar incidents.
The disclosure highlights growing scrutiny over AI cybersecurity testing as leading developers race to build more capable models while ensuring they remain safely contained during internal evaluations.


Arm Holdings Q1 Earnings Beat Estimates, Strong Q2 Outlook Fails to Lift ARM Stock
How an OpenAI safety test became a real-world cyberattack on the Hugging Face platform
Amazon Q2 Earnings Beat Estimates as AWS AI Growth Surges, But Q3 Revenue Forecast Disappoints
Sony Eyes $1.3 Billion Tamron Acquisition as Lens Maker Reviews Offer
Exosens H1 Profit Beats Forecasts as Defense Demand Drives Growth
GSK Unveils $2.52 Billion Cost-Cutting Plan to Accelerate Drug Pipeline
ASML, Applied Materials Slide as China DUV Chip Equipment Breakthrough Sparks Market Jitters
TSMC Gradually Restarts Japan Chip Plant After Kumamoto Earthquake
Meta CEO Zuckerberg Opposes U.S. Ban on Chinese AI Models, Warns Against Overregulation
Microsoft Stock Jumps as Azure Growth, AI Revenue Beat Expectations
Standard Chartered Beats Profit Forecasts as First-Half Earnings Rise 9%
World game at war: why some European nations have threatened a World Cup boycott
Meta-backed research finds exposure to ‘untrustworthy’ social media is rare. The fine print is less reassuring
Russia Charges Telegram Founder Pavel Durov With Facilitating Terrorism, Seeks International Arrest
Samsung Q2 Profit Surges on AI Memory Chip Demand, Forecasts Strong Second Half
Rio Tinto Stock Jumps as Strong Earnings, Higher Dividend and AI Metal Demand Boost Outlook
Chipotle Q2 Earnings Beat Expectations as Sales Growth Drives Higher 2026 Outlook 



