Anthropic Says Claude AI Hacked Three Organisations During Cybersecurity Tests

Anthropic reveals Claude AI breached three organisations during cybersecurity testing after a configuration error exposed systems to internet access.

Artificial intelligence company Anthropic has disclosed that its Claude AI models successfully hacked into the systems of three organisations during internal cybersecurity testing after a configuration error unintentionally granted them internet access.

The company said the incidents were uncovered during a review prompted by recent disclosures from rival OpenAI, which reported that some of its AI systems had breached external platforms, including AI development hub Hugging Face.

According to Anthropic, it examined more than 140,000 cybersecurity evaluations to determine whether its AI models had accessed the internet from testing environments that were intended to remain isolated.

The company found that a misconfiguration in systems operated by Anthropic and one of its testing partners allowed Claude to connect to the live internet during “capture-the-flag” exercises, where AI models are challenged to obtain information by penetrating other systems.

Anthropic said the earliest incidents occurred in April and confirmed that the affected organisations have since been notified. Neither the company nor the organisations detected the unauthorised intrusions at the time they occurred.

The San Francisco-based AI firm accepted responsibility for the security lapse and acknowledged that it could have conducted a more thorough review of its testing records. It added that the findings provide cautious optimism that stronger safeguards and additional investment can reduce similar risks in the future.

Cybersecurity expert David Allott said the incidents do not necessarily demonstrate a fundamentally new hacking capability. Instead, he noted that increasingly advanced AI agents can autonomously combine multiple capabilities, obtain credentials, access systems and carry out actions at machine speed.

The disclosure comes as technology companies invest heavily in AI agents capable of independently performing tasks such as research, customer service and cybersecurity operations.

Recent AI-related cybersecurity incidents have intensified calls for stricter oversight and stronger safety measures as autonomous systems become more capable.

The developments also follow OpenAI’s recent acknowledgement that some of its AI agents exceeded testing limits, including one that reportedly breached Hugging Face during a controlled evaluation. OpenAI has said it is investigating those incidents and plans to release a detailed technical report outlining its findings in the coming weeks.

Related posts

Seplat Signs $281.6 Million Deal To Sell 10% JV Stake To NNPC, Retains Operatorship

Microsoft Adds Record $450bn In Market Value After Blowout Earnings Ease AI Investment Concerns

Tinubu: We’ll Not Pay Ransom Or Negotiate With Terrorists, Murderers, Kidnappers

This website uses cookies to improve User experience. Learn More