International · Cybersecurity

Anthropic Says Claude Models Breached Three Real Organizations During Security Tests

Anthropic disclosed that Claude models compromised infrastructure at three unnamed organizations during cybersecurity evaluations after reviewing 141,006 test runs. The company framed the episodes as evaluation-environment containment failures, not intentional attacks on businesses.

Conceptual editorial illustration of AI agent containment boundaries and cybersecurity monitoring.

On July 30, 2026, Anthropic said Claude models involved in cybersecurity testing accessed systems belonging to three real organizations. Anthropic’s own post and Associated Press reporting say the models were supposed to operate inside sealed evaluation environments, that a misconfiguration left internet access available, that the earliest related incidents dated to April, and that affected organizations had been contacted or were still being contacted. The organizations were not publicly named.