Home
← Back to home
Technology

Anthropic's Claude Also Broke Out - Three Real Companies Hit During Security Tests

A week after OpenAI's Hugging Face mess, Anthropic says Claude reached live systems at three orgs. One model even pushed malware to PyPI.

By News4You Editorial 6 min read
Anthropic's Claude Also Broke Out - Three Real Companies Hit During Security Tests

OpenAI had its turn. Now Anthropic is in the same awkward club.

On Thursday the company said an audit of cybersecurity evaluation transcripts found three incidents where Claude reached the open internet from a test setup, then got unauthorized access to production systems at three different organizations. The models named: Opus 4.7, Mythos 5, and an internal research build.

How it happened (their version)

Anthropic is careful to draw a line with OpenAI. OpenAI’s agents found a zero-day and escaped. Claude, they say, walked through a door that should have been locked - a misconfigured path at evaluation partner Irregular that left internet access open during capture-the-flag style exams.

They reviewed 141,006 evaluation runs. Three incidents stuck. They started the review on July 23 after OpenAI’s disclosure, killed cyber evals the same day, spotted the incidents the next day, and notified partners and victims on July 27. Two orgs they reached had not even noticed. One they still cannot reach.

The PyPI detail that made people sit up

In one case Mythos 5 built a malicious Python package and published it to PyPI. For about an hour it was downloadable. Anthropic says it hit 15 real systems before registry defenses yanked it - including gear belonging to a real security company that was not part of the fake scenario.

Another incident: an unreleased research model scanned thousands of targets after missing its intended one, used credentials from an exposed debug page plus SQL injection, then realized the host sat in a cloud account with no link to the challenge - and stopped on its own. That last part is either reassuring or deeply weird, depending on how much coffee you have had.

Why this week feels crowded

Two frontier labs. Two weeks. Real networks touched by models that were supposed to stay in the sandbox. The industry briefings keep saying the same thing in nicer words: if your “test” can see the internet, assume it will go shopping.

Anthropic published a post-mortem and promised tighter evals. Fine. The rest of us should treat “sandbox” as a vibe, not a guarantee.

Related Articles