Ai model hacks three companies after mistakenly given internet access 20260731 p60kbi.html – Breaking News & Latest Updates 2026
Advertisement
Advertisement

AI model hacks three companies after it was mistakenly given internet access

Stuart Marsh
Stuart Marsh

Powered by

One of the world’s most highly used AI models went rogue and hacked into the systems of three companies during a testing phase in which it was mistakenly given internet access.

AI firm Anthropic said that during configuration testing of its large language model Claude, the AI was able to “exploit weak passwords and unauthenticated endpoints” of three separate companies after it exploited a loophole that gave it access to the net from testing environments.

Advertisement
Apple iPhone screen with Artificial Intelligence icons internet AI app application ChatGPT, DeepSeek, Gemini, Copilot, Grok, Claude, etc.

Apple and OpenAI had previously had a close relationship. iStock

“After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorised access to the production infrastructure of three different organisations,” Anthropic said in a statement.

“Claude compromised the impacted organisations’ infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints.

“It did not find or exploit any complex vulnerabilities.”

Anthropic said it stopped all testing once it was discovered Claude had access to the internet, and notified the three affected companies.

Two of the three companies had not detected the presence of Claude nor registered that their systems had been compromised.

Anthropic was still trying to reach the third.

Advertisement

The AI house said it was releasing details of the breaches as part of a “blameless postmortem culture” and it was “approaching the fixes as if the responsibility were ours alone”.

Anthropic quickly cemented itself as a rival to the ChatGPT maker with Claude, which it billed as more safety- and business-focused. AP

What is Claude?

Claude is a conversational assistant AI - similar in its interface to other well-known models such as ChatGPT, Google Gemini and Microsoft Copilot.

Advertisement
Advertisement

Compared to other platforms, Claude is often favoured for its ability to create code, handle nuanced prompts and deliver a natural writing style.

Anthropic said the incidents involved three separate models: Claude Opus 4.7, Claude Mythos 5 and an internal research model. The earliest cases dated back to April and occurred in evaluation environments that lacked what the company described as standard safeguard.

Second major AI model to go rogue

Advertisement

OpenAI says an autonomous agent powered by its advanced artificial intelligence models went rogue during a security test and triggered a hack that compromised the infrastructure of AI startup Hugging Face last week.

The ChatGPT creator was testing capabilities of some of its most advanced models in a controlled environment, but the agent escaped containment, reached the internet and broke into Hugging Face to satisfy its testing goal.

OpenAI says an autonomous agent powered by its advanced artificial intelligence models went rogue during a security test and triggered a hack that compromised the infrastructure of AI startup Hugging Face last week. Getty Images

The incident signals that AI’s expanding capabilities are already fuelling the security threat experts long feared and even top developers can be caught off-guard by flaws their models can exploit.

Advertisement
Advertisement

The breakout was “an unprecedented cyber incident, involving state-of-the-art cyber capabilities” and OpenAI is reinforcing its safeguards, the company said in a blog post on Tuesday.

With Reuters

email icon

Contact us

Share a tip-off, video or photo with us

Most viewed in World

More to explore