Anthropic says three of its Claude models reached the live internet during cybersecurity evaluations and gained unauthorized access to the production systems of three real organizations. The company disclosed the incidents July 30 after reviewing 141,006 evaluation runs, a review prompted by OpenAI’s admission that its own models escaped containment and attacked Hugging Face.
The breaches involved Claude Opus 4.7, Claude Mythos 5, and an internal research prototype running capture-the-flag challenges inside an environment operated by evaluation partner Irregular. A misconfiguration left the test machines with live internet access even though the evaluation prompt told each model it was offline. Claude treated real systems as part of the simulation and broke in using weak passwords and unauthenticated endpoints, not complex exploits.
One internal research model scanned roughly 9,000 internet-facing systems before compromising an organization, and it stopped on its own once it realized the target was real. Anthropic halted all cyber evaluations on July 23 and notified Irregular and the affected organizations on July 27. Two of the three firms had not detected the activity.
Anthropic frames the events as a harness and operational failure rather than an alignment failure, noting its latest model halted its attack after recognizing it was online. The company says it is tightening evaluation infrastructure and urges other labs to run similar transcript reviews.