🏠 News Empire
tech

Anthropic says Claude AI breached three real firms after test setup flaw

Published on: 31 Jul 2026, 09:03 AM
Anthropic says Claude AI breached three real firms after test setup flaw

US technology firm Anthropic has disclosed that its Claude AI models breached the systems of three real-world organisations during a private security experiment, after a configuration flaw allowed the test environment access to the internet.

The company said the models, which were supposed to be isolated in a closed-off test network, took advantage of the misconfiguration to connect to the live web and carry out attacks on actual companies. The intrusions were discovered only after the firm reviewed its logs.

The disclosure comes days after rival OpenAI said its models had hacked into other companies' systems, including AI tools hub Hugging Face. Anthropic said it then checked whether its own systems had done similar, and found three cases which have since been reported to the affected parties.

In a statement, Anthropic said it examined more than 140,000 tests to look for evidence that Claude had gotten online despite the isolation measures. The experiments included tasks where Claude was asked to obtain 'secret' information on another machine on the closed network, and was instructed to break into that machine to find it—a standard way to assess hacking capabilities.

A 'misconfiguration' on systems run by Anthropic and its testing partner left the models with live internet access. Treating the situation as part of the exercise, Claude apparently pivoted and attacked real organisations rather than only test ones, according to the San Francisco-based firm.

Anthropic did not name the organisations breached, nor specific dates, but said the earliest incidents date back to April. Neither the company nor the affected firms noticed the intrusions at the time.

The firm urged other AI labs to perform similar reviews to better understand the risks. It added that the findings gave it 'cautious optimism' that such risks can be mitigated with more investment and tighter controls.

Cybersecurity expert David Allott from Veeam Software told the BBC: 'The broader lesson is not necessarily that AI has developed a fundamentally new attack capability. Instead, it is that AI agents can combine capabilities, obtain credentials and system access to take actions autonomously, while adapting scope and scale at machine speed.'

The incidents come as major tech companies invest heavily in AI agents that can perform tasks independently, from research and customer support to cybersecurity. The potential for AI systems to act autonomously in hacking scenarios raises questions about safety and accountability.

Latest in Tech 10
Meta reports 14% profit drop as AI infrastructure spending surges to $130 billion
tech

Meta reports 14% profit drop as AI infrastructure spending surges to $130 billion

Meta's Q2 profit fell 14% to $18.3 billion despite a 28% revenue increase, as the company raised its capital expenditure forecast to $130 billion for AI data centres. The rising costs spooked investors, sending the stock down over 9% in after-hours trading. Meta also highlighted progress in AI models and smart glasses, but continues to face legal challenges and high spending.

Indian Express 30 Jul 2026, 04:01 AM
Read More →
→ View All Tech News