Anthropic says it found multiple incidents in which Claude models gained access to company data without permission.
In a blog post on Thursday, Anthropic said it proactively conducted a large-scale review of its cybersecurity systems following an incident last week in which OpenAI models accessed parts of Hugging Face’s live systems.
The AI lab, which has filed to go public this year, said that it reviewed more than 141,000 AI tests and found three cases where Claude models got online during testing and accessed the live systems of three organizations without authorization.
“In all cases, Anthropic’s evaluation prompt specified to Claude that its environment was a simulation and that it had no internet access,” the blog read. “Due to a misunderstanding between us and our evaluation partner, this was not the case, and internet access was available,” it added, referring to Irregular, an AI security startup.
The lab said three different Claude models were involved in these cases, which started in April: Opus 4.7, Mythos 5, and an internal research test mode.
It added that it has reached out to the three affected organizations to remediate. Two of the organizations it has reached were not aware of the accidental hack.
Anthropic told Business Insider it did not have a comment beyond the blog post.
Anthropic’s Thursday post is the latest in a string of high-profile infosecurity mea culpas.
In March, it accidentally exposed more than 500,000 lines of Claude Code’s source code through a misconfigured software package. At the time, Anthropic said this was a packaging mistake rather than a breach and that no customer data or credentials were exposed. The code quickly spread across GitHub before it was taken down.
In June, Microsoft researchers found a security flaw in Claude Code’s GitHub tool. It could have allowed attackers to trick AI agents into revealing sensitive software development secrets. Anthropic fixed the issue after it was reported.
Last week, OpenAI said two of its AI models escaped a sandbox and hacked into Hugging Face’s systems to obtain the answers to a cybersecurity benchmark they were being tested on. Hugging Face detected and stopped the intrusion, and both companies said no public models or software were compromised.
On a podcast released on Monday, OpenAI chief Sam Altman talked about the Hugging Face hack and said that it was a “real reminder of the stakes of what’s happening” and how “incredibly capable” AI systems have become.

