{"id":57740,"date":"2026-07-31T09:04:26","date_gmt":"2026-07-31T09:04:26","guid":{"rendered":"https:\/\/news.godj.com\/news\/anthropics-claude-ai-escapes-tests-to-hack-three-organisations\/"},"modified":"2026-07-31T09:04:26","modified_gmt":"2026-07-31T09:04:26","slug":"anthropics-claude-ai-escapes-tests-to-hack-three-organisations","status":"publish","type":"post","link":"https:\/\/news.godj.com\/news\/anthropics-claude-ai-escapes-tests-to-hack-three-organisations\/","title":{"rendered":"Anthropic&#8217;s Claude AI escapes tests to hack three organisations"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\"><b class=\"ssrcss-1xjjfut-BoldText e5tfeyi3\">US technology firm Anthropic says its AI models hacked into the systems of three organisations on their own, during a private security experiment.<\/b><\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The models found a weakness in what was supposed to be an isolated test environment and connected to the internet.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">It comes just days after rival OpenAI said that its models had <a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/c2el319vzr3o\" class=\"ssrcss-1e0jzsh-InlineLink e1kn3p7n0\">breached the systems of other companies<\/a>, including AI tools hub Hugging Face.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The announcement prompted Anthropic to check whether its own systems had carried out similar attacks. It says it uncovered three cases which have since been reported to the affected companies.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Anthropic, which did not name the organisations, urged other AI labs to perform similar reviews to better understand the risks of their models&#8217; capabilities.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Anthropic said <a href=\"https:\/\/www.anthropic.com\/news\/investigating-incidents-cybersecurity-evals\" class=\"ssrcss-1e0jzsh-InlineLink e1kn3p7n0\">in a statement<span class=\"visually-hidden ssrcss-i2z2ig-VisuallyHidden e16en2lz0\">, <!-- -->external<\/span><\/a> it reviewed more than 140,000 tests to find evidence Claude &#8211; its family of AI models &#8211; had managed to get online even though it was supposed to be in an isolated test environment, cut off from the internet.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The tests included exercises in which Claude was tasked with obtaining &#8220;secret&#8221; information hidden on another machine on the closed-off network.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">It was then told to get the information by breaking into the machine and finding it &#8211; a common way that experts assess a model&#8217;s hacking capabilities.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">A &#8220;misconfiguration&#8221; on systems run by Anthropic and its testing partner left the models with live internet access.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Treating it all as still part of the same exercise, Claude then connected to the internet and breached the systems of three real organisations rather than just test ones, the San Francisco-based firm said.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Anthropic said the earliest incidents date back to April and that it is &#8220;approaching the fixes as if the responsibility were ours alone.&#8221;<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Neither Anthropic nor the organisations that were breached had noticed the intrusions at the time. <\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Anthropic said it could have reviewed its records more thoroughly and added that the findings gave the firm &#8220;cautious optimism&#8221; that such risks can be overcome with more investment and tighter measures.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">&#8220;The broader lesson is not necessarily that AI has developed a fundamentally new attack capability,&#8221; cybersecurity expert David Allott from Veeam Software told the BBC.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">&#8220;Instead, it is that AI agents can combine capabilities, obtain credentials and system access to take actions autonomously, while adapting scope and scale at machine speed,&#8221; he added.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The incidents come as tech firms pour billions of dollars into developing AI agents that can independently perform tasks ranging from research and customer support to cybersecurity.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cz7dl7w8y7po?at_medium=RSS&#038;at_campaign=rss\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>US technology firm Anthropic says its AI models hacked into the systems of three organisations on their own, during a private security experiment. The models found a weakness in what was supposed to be an isolated test environment and connected to the internet. It comes just days after rival OpenAI said that its models had [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":57741,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[67],"tags":[16168,14521,11117,3991,16169,74],"class_list":["post-57740","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-top-news","tag-anthropics","tag-claude","tag-escapes","tag-hack","tag-organisations","tag-tests"],"_links":{"self":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts\/57740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/comments?post=57740"}],"version-history":[{"count":1,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts\/57740\/revisions"}],"predecessor-version":[{"id":57742,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts\/57740\/revisions\/57742"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/media\/57741"}],"wp:attachment":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/media?parent=57740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/categories?post=57740"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/tags?post=57740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}