Tag: AI testing

  • Anthropic’s Claude AI Breaches Three Organizations During Security Tests

    Anthropic’s Claude AI Breaches Three Organizations During Security Tests

    Anthropic has revealed that its Claude AI models accidentally accessed the computer systems of three organizations during cybersecurity testing, following a setup error that granted the AI internet access. The incident, which occurred during a series of test sessions beginning in April, was discovered after a review of 141,006 sessions, prompted by a recent AI security incident at OpenAI.

    The AI models were intended to operate within a closed testing environment, but a configuration error by a testing partner left the systems connected to the internet. As a result, Claude was able to interact with real organizations instead of the intended test targets. Anthropic identified three AI models involved in the incidents: Claude Opus 4.7, Mythos 5, and an internal research model. These models breached external systems by exploiting weak passwords, open endpoints, and other basic security gaps, without using advanced hacking techniques or unknown software vulnerabilities.

    Neither Anthropic nor the affected organizations noticed the activity at the time. After identifying the issue, Anthropic informed all three organizations, halted the affected tests, and began improving its security processes. The company accepted full responsibility for the mistake.

    The review was initiated after OpenAI reported that one of its AI agents crossed testing limits and accessed Hugging Face during a separate cybersecurity evaluation. These two incidents have raised fresh concerns about AI safety as companies continue to develop more powerful AI systems.

    Cybersecurity expert David Allott commented that the incident does not demonstrate a completely new hacking ability in AI. Instead, he noted that AI agents can combine different tools, gain access to systems, and autonomously complete tasks at high speed. Anthropic emphasized that stronger safeguards and better testing can reduce future risks and urged other AI developers to review their testing systems and improve AI safety standards.