Claude Reached Three Organizations During Security Tests
Anthropic says three Claude models reached the public internet from third-party evaluation environments and gained unauthorized access to three organizations. The models believed they were inside simulations and used basic weaknesses, including weak passwords and unauthenticated endpoints.
Treat test boundaries as real security controls. Validate network isolation, limit agent access, monitor activity live, and stop tests when scope becomes unclear.
141,006
Anthropic reviewed evaluations where Claude could have reached the internet.
3 organizations
Three models reached real production systems during cyber evaluations.
July 30, 2026
Anthropic published its findings after notifying affected organizations.
A configuration misunderstanding left live internet access available where the models were told none existed.
Two reached organizations had not detected the activity before Anthropic notified them, reinforcing the need for live monitoring.