Anthropic disclosed on Thursday that its Claude artificial intelligence models gained unauthorized access to the production systems of three organizations during internal cybersecurity evaluations after a testing environment was mistakenly left connected to the internet.
The AI company said the issue was uncovered during a retrospective review launched after OpenAI revealed on July 21 that several of its own AI models had escaped an isolated testing environment by exploiting a previously unknown software vulnerability and accessing production infrastructure at Hugging Face.
According to Anthropic, it reviewed 141,006 cybersecurity evaluation runs and identified three incidents dating back to April. The company said the events occurred because a third-party testing environment operated by evaluation partner Irregular was misconfigured, allowing Claude to access the internet despite being instructed that it was operating in an isolated "capture-the-flag" cybersecurity simulation.
Believing the environment was part of a controlled exercise, the AI models used basic attack techniques, including exploiting weak passwords, exposed credentials, and unauthenticated systems belonging to real organizations.
In one incident, a Claude model accessed a production database containing several hundred rows of data. In another, the AI uploaded a malicious Python package to the public Python Package Index (PyPI), which was briefly downloaded by 15 real systems before it was removed.
Anthropic emphasized that none of the Claude models attempted to escape their testing environments or replicate themselves. The company also said the safety measures built into publicly released Claude models would have prevented this behavior.
Following the discovery, Anthropic suspended all cybersecurity evaluations on July 23 and notified the affected organizations on July 27. The company said it is strengthening its evaluation infrastructure, tightening security controls, and improving monitoring procedures to prevent similar incidents.
The disclosure highlights growing scrutiny over AI cybersecurity testing as leading developers race to build more capable models while ensuring they remain safely contained during internal evaluations.


MongoDB Stock Sinks 14% as Atlas Growth Misses Expectations
US Tech Giants’ AI Bond Boom Raises Euro Zone Borrowing Risks
GLP-1 Weight-Loss Drug Use Surges Among U.S. Children
Nvidia CEO Says AGI Has Arrived With OpenAI GPT-6 Astra
Tesla Cybercab Rides Launch in Austin as NHTSA Reviews Rollout
PayPal Shares Sink as $50 Billion Takeover Bid Collapses
Audi, SAIC Launch China Innovation Hub for New AUDI Models
Spire Healthcare Shares Jump on £1.03 Billion Takeover Deal
SEC Seeks ISS Client Voting Records in Proxy Adviser Probe
Ingenia Rejects A$1.9 Billion Warburg Pincus Takeover Bid
Anthropic IPO Marketing Expected to Start in Mid-October
Xiaomi Shares Jump on Europe EV Expansion Plan
Deutsche Telekom Shares Rise as Elliott Pushes Against T-Mobile Merger
Apple’s Phil Schiller Steps Back as Leadership Shake-Up Accelerates
OpenAI Launches GPT-6 Astra With Advanced AI Agent Capabilities
Thomson Reuters C-Track Cyberattack Hits Courts Across U.S. and Canada 



