{"id":23035,"date":"2026-07-31T20:01:52","date_gmt":"2026-07-31T20:01:52","guid":{"rendered":"https:\/\/scannn.com\/anthropic-says-claude-models-hacked-3-organizations-during-cyber-tests\/"},"modified":"2026-07-31T20:01:52","modified_gmt":"2026-07-31T20:01:52","slug":"anthropic-says-claude-models-hacked-3-organizations-during-cyber-tests","status":"publish","type":"post","link":"https:\/\/scannn.com\/lv\/anthropic-says-claude-models-hacked-3-organizations-during-cyber-tests\/","title":{"rendered":"Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests"},"content":{"rendered":"\n<div>\n<style><![CDATA[\n#ar-widget{margin:0 0 2rem;font-family:-apple-system,BlinkMacSystemFont,\"Segoe UI\",sans-serif;}\n#ar-widget .ar-box{background:#fff;border:1px solid #e5e7eb;border-radius:12px;padding:1.1rem 1.4rem;}\n#ar-widget .ar-top{display:flex;align-items:center;gap:10px;margin-bottom:.85rem;}\n#ar-widget .ar-icon-wrap{width:38px;height:38px;border-radius:50%;background:#EEEDFE;display:flex;align-items:center;justify-content:center;flex-shrink:0;}\n#ar-widget .ar-meta{flex:1;min-width:0;}\n#ar-widget .ar-label{font-size:10px;color:#9ca3af;text-transform:uppercase;letter-spacing:.06em;margin:0 0 2px;}\n#ar-widget .ar-title-text{font-size:13px;font-weight:600;margin:0;color:#111827;white-space:nowrap;overflow:hidden;text-overflow:ellipsis;}\n#ar-widget .ar-progress-section{margin-bottom:.7rem;}\n#ar-widget #ar-seek{width:100%;height:4px;accent-color:#534AB7;cursor:pointer;display:block;margin:0;-webkit-appearance:none;appearance:none;background:#e5e7eb;border-radius:2px;outline:none;border:none;}\n#ar-widget #ar-seek::-webkit-slider-thumb{-webkit-appearance:none;width:14px;height:14px;border-radius:50%;background:#534AB7;cursor:pointer;}\n#ar-widget .ar-times{display:flex;justify-content:space-between;font-size:10px;color:#9ca3af;margin-top:3px;}\n#ar-widget .ar-controls{display:flex;align-items:center;gap:7px;flex-wrap:wrap;}\n#ar-widget .ar-controls button{border:1px solid #d1d5db;border-radius:8px;padding:5px 11px;background:#fff;cursor:pointer;font-size:12px;color:#374151;}\n#ar-widget .ar-controls button:hover{background:#f9fafb;}\n#ar-widget .ar-play-btn{border-color:#534AB7!important;color:#534AB7!important;font-weight:600;min-width:86px;text-align:center;}\n#ar-widget .ar-play-btn:hover{background:#EEEDFE!important;}\n#ar-widget .ar-speed-wrap{margin-left:auto;display:flex;align-items:center;gap:5px;}\n#ar-widget .ar-speed-wrap label{font-size:11px;color:#6b7280;}\n#ar-widget #ar-rate{border:1px solid #d1d5db;border-radius:6px;padding:3px 5px;font-size:11px;background:#fff;color:#374151;cursor:pointer;}\n#ar-widget #ar-status{font-size:11px;color:#9ca3af;margin:.65rem 0 0;padding-top:.65rem;border-top:1px solid #f3f4f6;}\n#ar-widget .ar-voice-row{display:flex;align-items:center;gap:6px;margin-top:8px;}\n#ar-widget .ar-voice-row label{font-size:11px;color:#6b7280;flex-shrink:0;}\n#ar-widget #ar-voice{flex:1;min-width:0;border:1px solid #d1d5db;border-radius:6px;padding:4px 6px;font-size:11px;background:#fff;color:#374151;cursor:pointer;}\n]]><\/style>\n<p class=\"wp-block-paragraph\">A cybersecurity test designed to measure<a href=\"https:\/\/hackread.com\/hacker-claude-code-gpt-4-1-mexican-records\/\"> Claude\u2019s hacking abilities<\/a> ended with Anthropic models gaining unauthorized access to three real organizations after an evaluation environment was mistakenly left connected to the internet. Claude had been told it was inside a simulation with no external access, so it treated the systems it found online as part of the exercise. Anthropic disclosed the incidents on July 30.<\/p>\n<p class=\"wp-block-paragraph\">The company began reviewing its cybersecurity evaluation transcripts after OpenAI disclosed that its own models had bypassed network restrictions and entered Hugging Face\u2019s production systems during a cyber evaluation. As <a href=\"https:\/\/hackread.com\/openai-models-breached-hugging-face\/\">Hackread.com previously reported<\/a>, the OpenAI models exploited an unknown vulnerability while searching for test answers. Anthropic reviewed 141,006 Claude evaluation runs and found six runs connected to three incidents.<\/p>\n<p class=\"wp-block-paragraph\">During each exercise, Claude was asked to find secret information known as a flag inside a fictional network. Anthropic\u2019s prompt said the environment was simulated and had no internet connection, but a misunderstanding with evaluation partner Irregular left live access available. The models therefore regarded real systems as test targets.<\/p>\n<h3 id=\"claude-opus-4-7\" class=\"wp-block-heading\"><strong>Claude Opus 4.7<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">One fictional company happened to share its name with a real website, leading Claude Opus 4.7 to attack the real organization during four runs. The model obtained application and infrastructure credentials, along with access to a database containing several hundred rows of production data. It continued after finding evidence that the target was real, reasoning that it might still belong to the exercise.<\/p>\n<h3 id=\"claude-mythos-5\" class=\"wp-block-heading\"><strong><strong>Claude Mythos 5<\/strong><\/strong><\/h3>\n<p class=\"wp-block-paragraph\">A separate exercise led Claude Mythos 5 to publish a <a href=\"https:\/\/hackread.com\/vmconnect-malicious-pypi-package-mimic-python-tools\/\" data-type=\"post\" data-id=\"91732\">malicious package on PyPI<\/a> after finding setup instructions that referred to a nonexistent package. The malicious package remained available for about an hour and ran on 15 real systems. One belonged to a cybersecurity company whose scanner installed the package, allowing Claude to obtain credentials and access more of its infrastructure before PyPI removed the file.<\/p>\n<h3 id=\"internal-research-model\" class=\"wp-block-heading\"><strong>Internal Research Model<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">Elsewhere, an internal research model scanned about 9,000 online targets after failing to reach its fictional one. It compromised a company\u2019s application using credentials exposed on a debug page and SQL injection. Once the model recognized that the system had no connection to the exercise, it stopped.<\/p>\n<p class=\"wp-block-paragraph\">None of the models needed advanced or <a href=\"https:\/\/hackread.com\/google-workspace-vulnerabilities-network-breaches\/\" data-type=\"post\" data-id=\"107275\">previously unknown vulnerabilities<\/a> in the three Anthropic incidents. They used weak passwords, exposed endpoints, and other familiar methods. Anthropic described the incidents as primarily an operational and evaluation failure, not evidence that Claude had formed an independent goal. <\/p>\n<p class=\"wp-block-paragraph\">The test models ran without the classifiers and monitoring applied to publicly available Claude services. The dedicated evaluation infrastructure had no access to Anthropic\u2019s internal systems or customer data.<\/p>\n<p class=\"wp-block-paragraph\">Anthropic\u2019s <a href=\"https:\/\/www.anthropic.com\/news\/investigating-incidents-cybersecurity-evals\" target=\"_blank\" rel=\"noopener\">security advisory<\/a> confirms that it halted its cyber evaluations on July 23, identified all three incidents the following day, and attempted to contact the affected organizations on July 27. Two had not detected the activity before Anthropic reached them and are now working with the company on remediation. Anthropic was still trying to reach the third organization when it published its account and did not disclose any names.<\/p>\n<p class=\"wp-block-paragraph\">Reading the disclosures from both labs, <a href=\"https:\/\/www.linkedin.com\/in\/dianakelleysecuritycurve\" target=\"_blank\" rel=\"noopener\">Diana Kelley<\/a>, chief information security officer at Noma Security, a New York City-based AI security and governance platform, said access restrictions cannot depend on an AI agent correctly understanding its surroundings. <\/p>\n<p class=\"wp-block-paragraph\">\u201cDon\u2019t rely on intent, rely on controls,\u201d Kelley told Hackread.com. She recommended isolation, least privilege, identity-based authorization, runtime controls, policy enforcement and kill switches for agents performing lengthy autonomous tasks.<\/p>\n<p class=\"wp-block-paragraph\">Anthropic plans to validate internet access paths before tests, increase monitoring of evaluation logs and transcripts, and apply stricter checks to external vendors. It also asked other AI laboratories to review past evaluations for similar incidents.<\/p>\n<p><!-- CONTENT END 1 -->\n\t\t\t<\/div>\n<p><script id=\"powerkit-facebook-sdk-js\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js?ver=3.1.1#xfbml=1&#038;version=v17.0&#038;appId=&#038;autoLogAppEvents=1\"><\/script><br \/>\n<br \/><a href=\"https:\/\/hackread.com\/anthropic-claude-models-hacked-organizations-cyber-tests\/?utm_source=tldrinfosec\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A cybersecurity test designed to measure Claude\u2019s hacking abilities ended with Anthropic models gaining unauthorized access to three real organizations after an evaluation environment was mistakenly left connected to the internet. Claude had been told it was inside a simulation with no external access, so it treated the systems it found online as part of [&hellip;]<\/p>\n","protected":false},"author":16,"featured_media":23036,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[143],"tags":[],"class_list":["post-23035","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai"],"_links":{"self":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts\/23035","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/comments?post=23035"}],"version-history":[{"count":0,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts\/23035\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/media\/23036"}],"wp:attachment":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/media?parent=23035"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/categories?post=23035"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/tags?post=23035"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}