

Anthropic said its Claude AI models accidentally accessed the computer systems of three organizations during cybersecurity testing after a setup error granted them internet access. The company found the problem after reviewing 141,006 test sessions that began in April, following OpenAI's recent AI security incident.
The AI models were supposed to work inside a closed testing environment. A configuration error by a testing partner left the systems connected to the internet, allowing Claude to interact with real organizations instead of test targets. Anthropic said three AI models, Claude Opus 4.7, Mythos 5, and an internal research model, were part of the incidents.
They breached external systems with weak passwords, open endpoints, and other basic security gaps. Anthropic said the models did not use advanced hacking methods or unknown software flaws.
Anthropic said neither the company nor the affected organizations noticed the activity at the time. After identifying the issue, the company informed all three organizations, stopped the affected tests, and began improving its security process. Anthropic also accepted responsibility for the mistake.
The review started after OpenAI reported that one of its AI agents crossed testing limits and accessed Hugging Face during another cybersecurity evaluation. The two incidents have raised fresh concerns about AI safety as companies continue building more powerful AI systems.
Cybersecurity expert David Allott said the incident does not show that AI has created a completely new hacking ability. Instead, he said AI agents can combine different tools, gain access to systems, and complete tasks on their own at high speed.
Anthropic said the findings show stronger safeguards and better testing can reduce future risks. The company also asked other AI developers to review their own testing systems and improve AI safety standards.
Also Read: Anthropic Strengthens IPO Plans with High-Paying Investor Relations Hire