Anthropic admits its Claude AI broke into three companies during safety tests

Anthropic admitted that its popular Claude AI models recently managed to gain unauthorised access to systems belonging to three real organisations while conducting cybersecurity testing. The breaches, one of which dates back to April, went undetected for several months.
This admission comes on the heels of a similar one by OpenAI, who acknowledged one of its AI agents escaped a test environment and hacked the Hugging Face platform. In fact, it was this incident that prompted Anthropic to scrutinise its own records for similar cases.
After reviewing 141,006 test runs in which there was a possibility for Claude to go online, the company spotted three problematic ones involving its Opus 4.7 and Mythos 5 models, along with an unnamed model used for internal research.
In each case, Claude was carrying out “capture the flag” puzzles, common exercises involving a search for a piece of information hidden somewhere else on a network. The prompt specified that the environment was a simulation without an internet connection.
However, the test machines had been misconfigured and were connected to the live internet. Anthropic put this down to a misunderstanding between itself and its testing partner, Irregular, about how the environment should be set up.
Claude then made its way onto real systems and treated them as part of the exercise. Weak passwords and unprotected endpoints were used to breach the systems; Claude did not do anything clever to break in.
The firm stressed that its models had their usual safeguards turned off for testing; these are different from the public versions. It added that the two organisations it was able to reach did not realise anything had happened, while it was still trying to contact the third. Anthropic has now paused its cyber testing while it determines what went wrong.
For UK firms, the lesson here is a familiar one. Weak passwords and exposed services are the easiest way in, and the government-backed Cyber Essentials scheme sets out basic steps for guarding against them.