Anthropic released the latest security report revealing that its Claude series models accidentally accessed the internet due to a configuration issue in the testing environment and unauthorizedly entered the production systems of three different organizations. The incident involved Claude Opus4.7, the cybersecurity model Claude Mythos5, and a prototype model that had not yet been publicly released. Anthropic stated that this event was caused by a configuration error in the testing environment, not by the model actively breaking through security restrictions.

According to the report, these models were currently participating in an internal "Capture the Flag" security challenge, aiming to find hidden "flag" information within Anthropic's internal network. Due to a communication error between Anthropic and its evaluation partners, the models actually gained internet access, although the system still indicated that they could not connect to the internet. When the models discovered an external network entry point, they mistakenly identified the target systems on the internet as part of the training environment and performed unauthorized access to three institutions.
Anthropic stated that the models mainly used basic security vulnerabilities such as weak passwords to penetrate, and did not exploit complex vulnerabilities for attacks. The company also pointed out that the latest generation of models stopped further attacks after realizing that the targets belonged to a real internet environment, while some earlier models continued to execute tasks, leading to the impact on the three institutions.
After the incident was exposed, Anthropic conducted a comprehensive review of the testing process and admitted that the incident could have been avoided if network access paths had been fully verified before the test, log auditing had been strengthened, or the models had been clearly informed of their ability to access the internet. The company has notified the evaluation partners and the three affected institutions as of July 27th. Two of the institutions were previously unaware that their systems had been accessed without authorization, and the third institution is still being contacted.
Following OpenAI's previous disclosure that an AI agent successfully accessed the internet and entered the Hugging Face environment during testing, Anthropic's recent incident once again highlights that as AI agents' autonomous capabilities continue to grow, the isolation of testing environments, permission control, and security assessment mechanisms have become crucial areas that the industry needs to strengthen.

