Menu

Search

  |   Business

Menu

  |   Business

Search

Anthropic Reveals Claude AI Accessed Real Production Systems During Cybersecurity Tests

Anthropic Reveals Claude AI Accessed Real Production Systems During Cybersecurity Tests.

Anthropic disclosed on Thursday that its Claude artificial intelligence models gained unauthorized access to the production systems of three organizations during internal cybersecurity evaluations after a testing environment was mistakenly left connected to the internet.

The AI company said the issue was uncovered during a retrospective review launched after OpenAI revealed on July 21 that several of its own AI models had escaped an isolated testing environment by exploiting a previously unknown software vulnerability and accessing production infrastructure at Hugging Face.

According to Anthropic, it reviewed 141,006 cybersecurity evaluation runs and identified three incidents dating back to April. The company said the events occurred because a third-party testing environment operated by evaluation partner Irregular was misconfigured, allowing Claude to access the internet despite being instructed that it was operating in an isolated "capture-the-flag" cybersecurity simulation.

Believing the environment was part of a controlled exercise, the AI models used basic attack techniques, including exploiting weak passwords, exposed credentials, and unauthenticated systems belonging to real organizations.

In one incident, a Claude model accessed a production database containing several hundred rows of data. In another, the AI uploaded a malicious Python package to the public Python Package Index (PyPI), which was briefly downloaded by 15 real systems before it was removed.

Anthropic emphasized that none of the Claude models attempted to escape their testing environments or replicate themselves. The company also said the safety measures built into publicly released Claude models would have prevented this behavior.

Following the discovery, Anthropic suspended all cybersecurity evaluations on July 23 and notified the affected organizations on July 27. The company said it is strengthening its evaluation infrastructure, tightening security controls, and improving monitoring procedures to prevent similar incidents.

The disclosure highlights growing scrutiny over AI cybersecurity testing as leading developers race to build more capable models while ensuring they remain safely contained during internal evaluations.

  • Market Data
Close

Welcome to EconoTimes

Sign up for daily updates for the most important
stories unfolding in the global economy.