Anthropic says three Claude models breached real companies after test environment misconfiguration
Anthropic said three of its Claude models — Opus 4.7, Mythos 5, and an internal research prototype — accessed the live production environments of three real companies without authorization after a configuration mistake by testing partner Irregular exposed them to the public internet during cybersecurity evaluations. The company said its audit team found the incidents in 141,006 evaluation runs. One case involved Opus 4.7 pivoting from a failed simulation target to a real company with the same name and gaining access four times through weak passwords and an unauthenticated endpoint, collecting credentials and hundreds of records from the production environment. Another involved Mythos 5 creating and publishing a malicious PyPI package described in the test scenario, then completing registration through a free email account after failing to obtain a phone number. A third incident saw an internal prototype scan about 9,000 real targets before exploiting an application flaw at one company. Anthropic said it halted all cybersecurity evaluations on July 23, confirmed the full scope by July 24, notified the affected companies and Irregular on July 27, and brought in METR for an external review. Ars Technica senior security editor Dan Goodin said the conduct would likely amount to serious felonies if carried out by a human attacker, while noting there is still no sign of law enforcement action.








