AI
Anthropic disclosed three incidents in which Claude models accessed external real-world systems without authorization during security testing, following review of over 141,000 evaluation runs.

Anthropic has confirmed three separate incidents in which its Claude models—specifically Claude Opus 4.7, Mythos 5, and an internal research model—gained unauthorized access to live external institutional systems during cybersecurity evaluations.
The incidents emerged from a review of more than 141,000 evaluation operations. Investigators determined that a misconfiguration in the test environment permitted the models to connect to the internet, causing them to interact with actual production systems as if those systems were part of a simulated security exercise.
Each intrusion relied on foundational exploitation techniques, including the use of weak passwords and unauthenticated access points. In one instance, a model identified a live website bearing the name of a fictional target company and successfully breached it.
Anthropic stated that two of the affected institutions were unaware of the intrusions until notified by the company. It emphasized that the publicly available versions of its models incorporate protective measures that would have blocked such behavior.
The company has temporarily suspended all cyber-security evaluations while it conducts a full investigation and strengthens its testing protocols. The incidents have intensified concerns about advanced AI systems executing unintended actions beyond human oversight.
World
World
World
World