{"id":7131,"date":"2026-07-31T08:53:57","date_gmt":"2026-07-31T08:53:57","guid":{"rendered":"https:\/\/koshalsambada.in\/?p=7131"},"modified":"2026-07-31T08:53:57","modified_gmt":"2026-07-31T08:53:57","slug":"after-openai-anthropic-admits-its-claude-ai-models-hacked-into-three-real-companies-using","status":"publish","type":"post","link":"https:\/\/koshalsambada.in\/?p=7131","title":{"rendered":"After OpenAI, Anthropic admits its Claude AI models hacked into three real companies using\u2026 |"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<div class=\"e9jwa\">\n<div class=\"vdo_embedd\">\n<div class=\"GfdvZ\">\n<section class=\"_bIDB  clearfix id-r-component leadmedia undefined undefined  E9tg9 \" style=\"top:0px\">\n<div class=\"_bIDB\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">\n<div class=\"ypVvZ\">\n<div class=\"WGttI\"><img src=\"https:\/\/static.toiimg.com\/thumb\/msid-132761193,imgsize-29094,width-400,height-225,resizemode-4\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg\" alt=\"After OpenAI, Anthropic admits its Claude AI models hacked into three real companies using\u2026\" title=\"Three companies were hacked by Claude. Two only found out when Anthropic called.\" decoding=\"async\" fetchpriority=\"high\"\/><\/div>\n<\/div>\n<\/div>\n<div class=\"Ta7d_ img_cptn\"><span title=\"Three companies were hacked by Claude. Two only found out when Anthropic called.\">Three companies were hacked by Claude. Two only found out when Anthropic called.<\/span><\/div>\n<\/section>\n<\/div><\/div>\n<\/div>\n<p>Anthropic went looking through its own logs after <a href=\"https:\/\/timesofindia.indiatimes.com\/topic\/openai\" styleobj=\"[object Object]\" class=\"\" commonstate=\"[object Object]\" frmappuse=\"1\" target=\"_blank\" rel=\"noopener\">OpenAI<\/a> admitted its models had hacked Hugging Face. It found three companies whose production systems its own Claude models had broken into. <!-- -->Two of them had no idea until Anthropic phoned to tell them.<!-- --> The third has not been reached yet. And the earliest of these break-ins happened in April, which means the models had been quietly hitting real targets for three months while everyone assumed the tests were sealed.<span class=\"id-r-component br\" data-pos=\"6\"\/>The company laid it out in a post on July 30. Three models were involved: Claude Opus 4.7, Mythos 5 and an unreleased internal research model. They got in using what Anthropic calls basic techniques, which is to say weak passwords, unauthenticated endpoints, an exposed debug page and SQL injection. <!-- -->No zero-days, no clever exploits. The earliest incident dates to April, and neither Anthropic nor its testing partner noticed for three months.<span class=\"id-r-component br\" data-pos=\"11\"\/><\/p>\n<p><h2><b>Anthropic says Claude thought it was in a simulation, but the test environment was online<\/b><\/h2>\n<\/p>\n<p>The review was enormous. Anthropic combed through 141,006 evaluation runs, starting two days after OpenAI&#8217;s July 21 disclosure and halting all cyber testing that same day. It had all three incidents by the next morning and rang the affected organisations the following Monday.<span class=\"id-r-component br\" data-pos=\"15\"\/>Each model was running a capture-the-flag exercise, a standard security drill in which it hunts for a hidden piece of information on another machine. The tests were built with Irregular, a third-party evaluation partner.<span class=\"id-r-component br\" data-pos=\"17\"\/>Every prompt told Claude it was working inside a simulation with no internet access. A misconfiguration meant the environments were actually online. So when the models wandered onto real machines, they treated them as part of the exercise.<span class=\"id-r-component br\" data-pos=\"20\"\/>Unlike OpenAI&#8217;s models, Claude never had to break anything open. The internet was simply there, and the targets it found were badly secured.<span class=\"id-r-component br\" data-pos=\"22\"\/><\/p>\n<p><h2><b><keyword id=\"34557325\" type=\"General\" weightage=\"20\" keywordseo=\"claude-mythos\" source=\"keywords\">Claude Mythos<\/keyword> 5 uploaded a malicious Python package to PyPI, and 15 real systems ran it<\/b><\/h2>\n<\/p>\n<p>The most damaging case involved Opus 4.7. The fictional company it had been told to attack happened to share a name with a real one. Claude went after the real one and pulled out credentials and several hundred rows of production data. Across four runs, the model worked out the system was live and carried on anyway.<span class=\"id-r-component br\" data-pos=\"26\"\/>The strangest case belonged to Mythos 5. It found a document instructing developers to install a Python package that did not exist, and spotted the gap. To publish one under that name it needed a PyPI account, which needed an email, which needed a phone number. It failed to find a free phone service, failed to raise money for a paid one, backtracked, found an email provider that asked no questions, and uploaded the malware.<span class=\"id-r-component br\" data-pos=\"29\"\/>The package was live for about an hour. Fifteen real systems ran it. One was a security firm&#8217;s scanner that installs packages automatically to check them for malware, and Claude&#8217;s code executed, took the company&#8217;s credentials and reached deeper into its infrastructure.<span class=\"id-r-component br\" data-pos=\"32\"\/><\/p>\n<p><h2><b>Claude Opus 4.7 kept attacking after it knew, and Anthropic calls this a harness failure<\/b><\/h2>\n<\/p>\n<p>Mythos 5&#8217;s own reasoning shows it understood the stakes. It noted that publishing the package on the real internet would be an actual attack and not the intended solution, then talked itself out of that conclusion because it did not recognise the certificate authorities on its connections and because the calendar read 2026, which it decided proved the setup was staged.<span class=\"id-r-component br\" data-pos=\"36\"\/>The third model scanned roughly 9,000 hosts, compromised a company&#8217;s public-facing application, then noticed the machine sat in an unrelated cloud account and stopped on its own.<span class=\"id-r-component br\" data-pos=\"38\"\/>Anthropic calls this a harness and configuration failure rather than an alignment failure, and points out that the safeguards on its publicly available models would have blocked all of it. Those safeguards are switched off during capability testing by design. METR will conduct an independent review, and a redacted transcript of the PyPI attack is due within the week.<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/timesofindia.indiatimes.com\/technology\/tech-news\/after-openais-anthropic-admits-its-claude-ai-models-hacked-into-three-real-companies-using\/articleshow\/132761152.cms\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Three companies were hacked by Claude. Two only found out when Anthropic called. Anthropic went looking through its own logs after OpenAI admitted its models had hacked Hugging Face. It found three companies whose production systems its own Claude models had broken into. Two of them had no idea until Anthropic phoned to tell them. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":7132,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-7131","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-31"],"magazineBlocksPostFeaturedMedia":{"thumbnail":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","medium":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","medium_large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","1536x1536":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","2048x2048":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","blogsy-small":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","blogsy-small-tall":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","blogsy-small-square":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","blogsy-small-masonry":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","blogsy-medium":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","blogsy-medium-masonry":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","blogsy-large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg","blogsy-wide":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg"},"magazineBlocksPostAuthor":{"name":"admin","avatar":"https:\/\/secure.gravatar.com\/avatar\/8709732a479614e7a8aa24d3eb1b239f30dc6d90c61464ed495001e7a469d856?s=96&d=mm&r=g"},"magazineBlocksPostCommentsNumber":"0","magazineBlocksPostExcerpt":"Three companies were hacked by Claude. Two only found out when Anthropic called. Anthropic went looking through its own logs after OpenAI admitted its models had hacked Hugging Face. It found three companies whose production systems its own Claude models had broken into. Two of them had no idea until Anthropic phoned to tell them. [&hellip;]","magazineBlocksPostCategories":["\u0b26\u0b47\u0b36 \u0b2c\u0b3f\u0b26\u0b47\u0b36"],"magazineBlocksPostViewCount":1,"magazineBlocksPostReadTime":4,"magazine_blocks_featured_image_url":{"full":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg",400,225,false],"medium":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg",300,169,false],"thumbnail":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/three-companies-were-hacked-by-claude-two-only-found-out-when-anthropic-called.jpg",150,84,false]},"magazine_blocks_author":{"display_name":"admin","author_link":"https:\/\/koshalsambada.in\/author\/admin"},"magazine_blocks_comment":0,"magazine_blocks_author_image":"https:\/\/secure.gravatar.com\/avatar\/8709732a479614e7a8aa24d3eb1b239f30dc6d90c61464ed495001e7a469d856?s=96&d=mm&r=g","magazine_blocks_category":"<a href=\"#\" class=\"category-link category-link-31\">\u0b26\u0b47\u0b36 \u0b2c\u0b3f\u0b26\u0b47\u0b36<\/a>","_links":{"self":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts\/7131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7131"}],"version-history":[{"count":0,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts\/7131\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/media\/7132"}],"wp:attachment":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}