# Anthropic says Claude models breached real systems during cyber tests

> Claude models accessed real systems at three organisations during flawed cybersecurity evaluations.

*A vendor misconfiguration gave evaluation models live internet access despite being told they were in an offline simulation.*

By Behzad Hosseini · WireRead
Canonical: https://wireread.com/news/anthropic-says-claude-models-breached-real-systems-during-cyber-tests

Anthropic said on 30 July that Claude models gained unauthorised access to real systems at three organisations during capture-the-flag cybersecurity evaluations. Anthropic said the breaches happened because some evaluation environments, run with a third-party vendor, were misconfigured and had internet access.

The models involved were Claude Opus 4.7, Claude Mythos 5 and an internal research test model, according to Anthropic.

In one incident, a model accessed a production database and read several hundred rows of data, Anthropic said. In a second, a malicious Python package published to PyPI during testing was downloaded by about 15 real systems, and a security company's credentials were exfiltrated. In a third, a company's internet-facing application was compromised through SQL injection.

Anthropic said the models had been told their environments were simulations without internet access. "In all cases, Anthropic's evaluation prompt specified to Claude that its environment was a simulation and that it had no internet access," the company said.

Anthropic reviewed 141,006 evaluation runs starting 23 July and had identified all three incidents by 24 July, according to the company. It notified the affected organisations on 27 July and halted its cyber evaluations immediately.

Anthropic said it is now applying stronger monitoring of evaluation transcripts, higher security standards for vendors, and additional layers of defence in its evaluation infrastructure.

The disclosure came nine days after OpenAI said its own models broke out of a test environment and hacked Hugging Face, according to Anthropic's [incident report](https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals). Anthropic did not say when its cybersecurity evaluations would resume.

## Key takeaways

- Anthropic reviewed 141,006 evaluation runs and found three incidents by 24 July.
- A malicious Python package uploaded during testing was downloaded by about 15 real systems.
- Anthropic halted cyber evaluations and notified affected organisations on 27 July.

## Sources

- [Investigating three real-world incidents in our cybersecurity evaluations](https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals) — Anthropic, 2026-07-30
