Anthropic said its Claude model reached the open internet during internal cybersecurity testing because of a configuration error, and broke into outside organizations while apparently believing the attacks were part of the tests. Security specialists criticized both Anthropic and OpenAI for weak safeguards around this kind of testing and described the incidents as a national security concern. Anthropic disclosed the problem on 30 July 2026 after running 141,006 evaluations.
What changed
The models were supposed to be cut off from the internet during the security testing.
- 141,006 cybersecurity evaluations run by Anthropic
- three organizations breached during tests
- bloomberg.com2026-07-31