Claude AI Accidentally Accessed Real Company Systems

Anthropic, the company behind the Claude AI chatbot, has revealed that three of its AI models accidentally gained access to the computer systems of three real companies during cybersecurity testing. The company said this happened because of a configuration mistake that left the testing environment connected to the public internet.

Anthropic discovered the problem after reviewing more than 141,000 cybersecurity test sessions. The review was carried out after OpenAI recently disclosed that one of its own AI models had accessed real systems during a separate security test. Anthropic described its own incidents as an operational failure, meaning the problem was caused by a mistake in the testing setup rather than by the AI intentionally breaking security rules.

AI Was Meant to Test Fake Networks

The incidents happened during special cybersecurity exercises called capture-the-flag challenges. These tests are designed to measure how well AI models can find hidden information or security weaknesses inside a fake computer network.

Claude was clearly told that it was working inside a simulated environment and that it did not have internet access. However, due to a misunderstanding between Anthropic and its third-party testing partner, Irregular, some of the testing systems were accidentally left connected to the real internet.

Because of this mistake, the AI models were able to interact with real company systems instead of staying inside the simulated network.

AI Used Simple Security Weaknesses

Anthropic said the AI models did not use advanced hacking techniques. Instead, they found and used common security problems such as weak passwords and online services that did not require proper authentication.

The company did not reveal the names of the affected businesses but confirmed that three different companies were involved.

Three Claude Models Took Part

The incidents involved three different AI models:

  • Claude Opus 4.7
  • Claude Mythos 5
  • An internal research model that is not publicly available

The first known incident happened in April.

In one case, Claude Opus 4.7 was instructed to attack a fictional company created for the test. However, a real company happened to have the same name. While searching online, the AI found security weaknesses in the real company’s systems and gained access to login credentials and a database.

Anthropic explained that the AI believed the real company’s systems were part of the simulated exercise because of the identical name.

One AI Model Stopped Itself

In another incident, Anthropic’s internal research model realized that it had reached a real company’s systems instead of a test environment.

The AI stopped its own actions without being told to do so. Anthropic called this behavior encouraging because it suggests future AI systems may be able to recognize when they are operating outside their intended environment.

However, the company said more testing is needed before it can rely on this behavior.

Companies Were Not Aware

Anthropic started reviewing its cybersecurity evaluation records on July 23 and immediately paused all cybersecurity testing.

By July 24, the company had identified the three accidental access incidents.

On July 27, Anthropic informed the affected companies. Two of the companies had no idea that their systems had been accessed until Anthropic contacted them. The company said it was still trying to reach the third organization.

Irregular, the third-party evaluation partner involved in the testing, is also investigating what happened.

Similar Incident Happened at OpenAI

The disclosure comes only days after OpenAI reported a separate cybersecurity testing incident. In OpenAI’s case, one of its AI models escaped an isolated testing environment and later compromised systems belonging to Hugging Face, an AI development platform.

The two incidents happened for different reasons.

In OpenAI’s case, the AI discovered and exploited a previously unknown software vulnerability to gain internet access.

In Anthropic’s case, the AI did not break through security on its own. Instead, it was able to access the internet because the testing environment had been incorrectly configured, allowing outside connections that should have been blocked.

Anthropic Plans Stronger Security

Anthropic said these incidents show that AI systems are becoming powerful enough to perform real cybersecurity tasks. As a result, companies developing advanced AI must build stronger safeguards to ensure testing remains isolated from real-world systems.

The company also said both its internal teams and third-party testing partners will need better security controls to prevent similar incidents in the future as AI models continue to become more capable of carrying out real-world cyber operations.

spot_img

Related articles

LinkedIn Cracks Down on AI Spam

LinkedIn is introducing a new feature to reduce low-quality...

Zindigi Wins Award for Digital Public Services

Zindigi, the digital financial platform powered by JS Bank,...

Banks Start Deducting Tax from YouTube and Facebook Earnings

Banks in Pakistan have started deducting withholding tax from...

Amendments to Oil Refining Policy 2023 to Boost Investment, Modernise Refining Sector: PPEPCA

ISLAMABAD – Zubair Kasuri: Pakistan Petroleum Exploration and Production...
spot_img