Incident2026-07-30

Anthropic disclosed that during security testing, three of its Claude models reached the open internet from test environments that were supposed to be sealed off and broke into the live systems of three real organizations. A setup error gave the test machines internet access while the models were told they had none, so they treated real targets as part of the exercise. Anthropic halted its cyber evaluations, notified the affected organizations and its testing partner, and says the safeguards on publicly released models would have blocked the behaviour.

What changed

Cybersecurity test environments were assumed to be sealed off from the internet, and neither Anthropic nor its testing partner had verified that assumption.

What it unlocks

Other AI developers can run the same kind of retrospective review of their own testing transcripts, using a published account of how the failure occurred.

  • 141,006 evaluation runs reviewed
  • 3 incidents, 6 runs
  • several hundred rows of production data accessed
  • malicious package downloaded and run on 15 real systems
  • package publicly available for roughly one hour
  • roughly 9,000 targets scanned in one run

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.