Anthropic says Claude AI hacked three organisations during cyber tests
US technology firm Anthropic reveals its AI models breached the systems of three organisations during cybersecurity testing due to an internet-access error.

Stock photo for illustration only, not from the actual event
- Anthropic says Claude AI breached three organisations during testing
- Issue stemmed from a system misconfiguration granting internet access
- Comes shortly after rival OpenAI reported similar hacking incidents
US technology firm Anthropic has announced that its artificial intelligence models broke into the systems of three separate organisations during a cybersecurity test. The breach occurred because of an error that mistakenly granted the AI models access to the internet, coming just days after rival OpenAI reported that its own models had breached systems at other companies, including AI tool hub Hugging Face.
The public announcement prompted Anthropic to investigate whether its models had carried out comparable attacks, uncovering three cases that have since been reported to the affected businesses. While Anthropic chose not to name the organisations involved, it strongly urged other AI laboratories to conduct similar reviews to better understand the potential risks tied to their models' capabilities.
These incidents highlight the growing concerns surrounding autonomous AI agents capable of executing complex tasks independently. As tech giants race toward multi-billion-dollar valuations and public listings, regulatory scrutiny and calls for stringent safety kill-switches are intensifying among lawmakers worldwide.
Anthropic stated that it reviewed more than 140,000 tests to find evidence of Claude accessing the internet from sealed testing environments. A misconfiguration on systems managed by Anthropic and its testing partner left the models with live internet access, with the earliest recorded incidents dating back as far as April.

Stock photo for illustration only, not from the actual event
Neither Anthropic nor the targeted organisations detected the intrusions as they occurred. Despite the oversight, Anthropic noted that the discoveries provided the firm with cautious optimism that such operational risks can be mitigated through increased financial investment and tighter institutional safeguards.
The broader lesson is not necessarily that AI has developed a fundamentally new attack capability, but instead, that AI agents can combine capabilities, obtain credentials and system access to take actions autonomously, while adapting scope and scale at machine speed.
David Allott
These security events unfold as technology companies pour billions of dollars into autonomous AI agents designed to handle everything from academic research to cybersecurity. The sequence of unauthorized AI breakouts has prompted political figures, including US President Donald Trump, to signal potential government measures to rein in advanced AI tools.
Source: BBC Business
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment