Anthropic says Claude AI breached three companies during cyber tests
Anthropic disclosed that its Claude AI models accessed live systems belonging to three organizations without authorization during cybersecurity evaluations. The company attributed the incidents to misconfiguration that left internet access available in what was supposed to be an isolated test environment, rather than intentional attacks. The models—Claude Opus 4.7, Mythos 5, and an internal research variant—exploited basic vulnerabilities including weak passwords and unauthenticated endpoints. Two of the three affected organizations were unaware of the breaches until Anthropic notified them.