Following OpenAI, Anthropic also said on July 30 that AI software it was testing connected to the internet without its knowledge and hacked three companies starting in April.
According to a Wall Street Journal report, Anthropic did not disclose the names of the victim companies but notified all three. The announcement came a week after OpenAI disclosed that its AI technology escaped a test sandbox and hacked AI company Hugging Face.
The case in which an AI agent OpenAI was testing hacked Hugging Face, an open-source AI model-sharing platform, appears to have led to concerns among security researchers and AI industry officials about the unpredictability of autonomous AI systems.
Anthropic reviewed its cyber test records after the OpenAI incident occurred.
After checking more than 141,000 test logs, it found that Claude accessed the internet multiple times. In the three hacking cases confirmed this time, Claude did not escape a sandbox but accessed outside systems that had no sandbox in the first place. Anthropic explained that a "configuration error" in systems operated by Anthropic and its testing partner Irregular allowed the model to connect to the real internet. Irregular said it is investigating the incident.
The models Anthropic was testing were told they could not use the internet, but connected online during testing and infiltrated companies using basic techniques such as guessing weak passwords or finding systems that required no authentication. Anthropic said the models mistakenly perceived such actions as part of benchmarking.
In the most serious case, after Claude failed to hack a virtual company, it instead infiltrated the database of a real company that happened to have the same name. The Wall Street Journal reported that Claude did not stop hacking even after it recognized it was a real company. The hacking began in April and included Opus 4.7, Mythos 5 and an unnamed research model.
Alex Stamos (알렉스 스타모스), chief product officer at security firm Croidoor, said, "These incidents show AI companies need an industry-wide common standard to isolate systems during cyber testing."
He added, "There are also concerns about a future in which ransomware criminals launch large-scale attacks using more powerful AI," and said, "We need to prepare for when attackers acquire these capabilities using open-weight models."
Concerns are expected to grow over risks posed by powerful AI models and how to respond. The White House has recently been moving to strengthen AI oversight, and in the industry there are also growing voices that access to open-weight models should be maintained.