• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

He worked 100-hour weeks to save a nearly bankrupt boat company. At 83, he’s just turned down $400 million for it—and gave it all to charity instead

2

Costco's $14 million email settlement: Who qualifies for an up-to $500 payment and how to claim before the Aug. 24 deadline

3

Tim Cook signed off on his final Apple earnings call with a warning about a ‘hundred year flood’ in memory chip pricing

1

He worked 100-hour weeks to save a nearly bankrupt boat company. At 83, he’s just turned down $400 million for it—and gave it all to charity instead

2

Costco's $14 million email settlement: Who qualifies for an up-to $500 payment and how to claim before the Aug. 24 deadline

3

Tim Cook signed off on his final Apple earnings call with a warning about a ‘hundred year flood’ in memory chip pricing
EnvironmentAnthropic

Anthropic says its Claude models escaped a testing environment and hacked three real companies

By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
July 31, 2026, 9:08 AM ET
Dario Amodei speaking into a microphone.
Anthropic CEO Dario AmodeiSamyukta Lakshmi/Bloomberg via Getty Images
Add Fortune on Google for similar content.

Anthropic has said that its Claude models broke out of what was supposed to be an isolated testing environment and gained unauthorized access to the systems of three real organizations. If that sounds familiar, it’s because it’s the second major AI lab this month to disclose that its technology had staged real-world autonomous hacks. 

Recommended Video

The disclosure comes just over a week after OpenAI—Anthropic’s bitter rival in the AI race—revealed that its models had exploited a previously unknown vulnerability to escape an isolated test environment and breached the company Hugging Face, an open-source AI platform. That incident prompted Anthropic to launch its own review of cybersecurity evaluation transcripts, the company said in a post published Thursday.

The AI lab reviewed 141,006 evaluation runs—individual test sessions in which a model is set a task inside a controlled environment and its actions logged for review—in which Claude could have obtained internet access and found three incidents in which the model reached the open internet from within the testing environment of a third-party evaluation partner, and then went on to compromise real infrastructure. The earliest incident dates back to April.

In each case, Claude had been assigned a capture the flag exercise, a standard method labs use to test a model’s hacking ability by asking it to retrieve hidden information from another machine on a simulated network. Anthropic’s prompts told Claude it had no internet access. However, a misconfiguration by the third-partner, Irregular, meant that wasn’t true.

Believing it was still operating inside the simulation, Claude went looking for its target and, in each incident, found and compromised real systems instead, using basic methods such as weak passwords and unauthenticated endpoints, according to Anthropic.

The most serious case involved Claude Opus 4.7, which extracted credentials and accessed a database containing several hundred rows of production data belonging to a real company that happened to share a name with the fictional target in its evaluation. Anthropic said this was the only incident in which the model kept attacking after it had apparent evidence the system was real.

In a second incident, Claude Mythos 5 built and published a malicious Python package—a bundle of pre-written code that developers commonly download to add functionality to their own software—to a public registry, reasoning at one point that the exercise was still a simulation because it didn’t recognize the certificate authorities—the organizations that issue the digital certificates used to verify a website or server is genuine—securing its connections. The package was live for about an hour and was installed on 15 real systems, including a security company’s malware scanner, allowing Claude to obtain and use that company’s credentials.

A third incident, involving an internal research model, saw Claude scan roughly 9,000 targets before compromising one company’s internet-facing application. That model stopped once it concluded, on its own, that the system it had breached was not part of the exercise.

Anthropic said none of the affected organizations had detected the intrusions before being notified, and that it is still working to reach one of the three. The company described the incidents as more of an operational failure than an alignment failure. The lab also noted that its newest model was the only one of the three to halt its attack once it recognized the environment was real.

Charlie Eriksen, a security researcher at Aikido Security, said it was encouraging to see Anthropic proactively reviewing its evaluation traces and disclosing the findings quickly, but that it was concerning that the tests seemed to lack real-time monitoring.

“It’s only unsettling because of the sheer capability, speed, and scale these agents can operate at. They’re not doing anything humans haven’t done before. That part isn’t new. What’s genuinely concerning is that they’re acting without meaningful human oversight, judgment, or intervention,” he said. 

“The OpenAI incident raised legitimate questions about the legal and ethical implications of LLM agents going rogue,” he added. “This only reinforces those concerns. If an autonomous agent causes harm or acts outside its intended boundaries, who is ultimately responsible?”

Both OpenAI’s and Anthropic’s disclosures land as both companies are preparing for stock market listings expected to value each company at more than $1 trillion. As fears around the risks of autonomous agents increase and calls mount for the industry to at least consider “pacing” frontier development, both companies’ upcoming IPOs could be under threat. 

Subscribe to Fortune Gulf Brief. Every Tuesday, this new newsletter delivers clear-eyed, authoritative intelligence on the deals, decisions, policies, and power shifts shaping one of the world’s most consequential regions, written for the people who need to act on it. Sign up here.
About the Author
By Beatrice NolanTech Reporter
Twitter icon

Beatrice Nolan is a tech reporter on Fortune’s AI team, covering artificial intelligence and emerging technologies and their impact on work, industry, and culture. She's based in Fortune's London office and holds a bachelor’s degree in English from the University of York. You can reach her securely via Signal at beatricenolan.08

See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Environment

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • TikTok icon
  • YouTube icon

Latest in Environment

mn
Cybersecuritycyber
Iran-style hackers shut down a Minnesota town’s water plant. Only the water tower saved it
By Jamie Stengle, Eric Tucker and The Associated PressJuly 31, 2026
47 minutes ago
danube
Environmentclimate change
The Dry Danube: Europe’s legendary river got so low that a cruise ship ran out of food and water
By Justin Spike and The Associated PressJuly 31, 2026
50 minutes ago
Dario Amodei speaking into a microphone.
EnvironmentAnthropic
Anthropic says its Claude models escaped a testing environment and hacked three real companies
By Beatrice NolanJuly 31, 2026
54 minutes ago
s
Environmentwildfires
Climate change made Spain’s wildfires 20 times more likely, study finds
By Seth Borenstein and The Associated PressJuly 31, 2026
1 hour ago
Photo of two polar bears
Environmentclimate change
Polar bears roll in beds of ice cubes at Prague Zoo as Europe battles record heat
By The Associated PressJuly 30, 2026
24 hours ago
Scientist on wildfires: ‘we have our foot on the gas pedal’ but ‘we’ve lost the brakes’
EnvironmentEnvironment
Scientist on wildfires: ‘we have our foot on the gas pedal’ but ‘we’ve lost the brakes’
By Seth Borenstein and The Associated PressJuly 29, 2026
2 days ago

Most Popular

He worked 100-hour weeks to save a nearly bankrupt boat company. At 83, he’s just turned down $400 million for it—and gave it all to charity instead
Success
He worked 100-hour weeks to save a nearly bankrupt boat company. At 83, he’s just turned down $400 million for it—and gave it all to charity instead
By Preston ForeJuly 29, 2026
2 days ago
Costco's $14 million email settlement: Who qualifies for an up-to $500 payment and how to claim before the Aug. 24 deadline
Retail
Costco's $14 million email settlement: Who qualifies for an up-to $500 payment and how to claim before the Aug. 24 deadline
By Sydney LakeJuly 29, 2026
2 days ago
Tim Cook signed off on his final Apple earnings call with a warning about a ‘hundred year flood’ in memory chip pricing
Big Tech
Tim Cook signed off on his final Apple earnings call with a warning about a ‘hundred year flood’ in memory chip pricing
By Alexei OreskovicJuly 30, 2026
14 hours ago
'Am I paying for the vibes?' Gen Z says it hates capitalism, but their spending patterns show they just don't like being ripped off
Retail
'Am I paying for the vibes?' Gen Z says it hates capitalism, but their spending patterns show they just don't like being ripped off
By Nick LichtenbergJuly 30, 2026
1 day ago
The rise of 'conspicuous waiting': The 19th-century economic theory that explains why Gen Z posts their place in line
Retail
The rise of 'conspicuous waiting': The 19th-century economic theory that explains why Gen Z posts their place in line
By Tatiana SatauaJuly 31, 2026
7 hours ago
Current price of oil as of July 30, 2026
Personal Finance
Current price of oil as of July 30, 2026
By Joseph HostetlerJuly 30, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.