Anthropic says its AI models hacked 3 organizations during testing

Advertisement

Advertise with us

Anthropic said its artificial intelligence models hacked into three other organizations during testing, just days after ChatGPT maker OpenAI raised concerns over AI controls after it disclosed its rogue models hacked another company.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Anthropic said its artificial intelligence models hacked into three other organizations during testing, just days after ChatGPT maker OpenAI raised concerns over AI controls after it disclosed its rogue models hacked another company.

Anthropic, the San Francisco-based AI company behind Claude, posted on its website Thursday that it discovered the three incidents after reviewing more than 141,000 evaluation runs.

It had launched a “large-scale” cybersecurity review which specifically looked for evidence whether its AI models were able to access the internet from within testing environments that should have been sealed off, in response to the OpenAI incident, Anthropic said.

FILE - Pages from the Anthropic website and the company's logo are displayed on a computer screen in New York, Feb. 26, 2026. (AP Photo/Patrick Sison, File)
FILE - Pages from the Anthropic website and the company's logo are displayed on a computer screen in New York, Feb. 26, 2026. (AP Photo/Patrick Sison, File)

Anthropic said the models involved in the incidents were Claude Opus 4.7, Claude Mythos 5 and an internal research test model. The earliest incidents date to April, the AI company said.

“Claude compromised the impacted organizations’ infrastructure using basic techniques,” Anthropic said, such as exploiting weak passwords.

In all three incidents, the AI models were tasked with a “capture the flag” cybersecurity challenge, which Anthropic said has been one of the ways it assesses a model’s cyber capabilities.

The models were given a fictional scenario and told a piece of secret information, or the “flag,” had been hidden on a different machine on the network with the objective of breaking in and retrieving it, it said.

It added that it had already reached out to the affected organizations, which it did not name. Two of them said they had not previously detected the activity. Anthropic said it was “continuing to reach out to the third.”

Anthropic said it conducted its review with Irregular, which describes itself as the “first frontier security lab.”

“Addressing these risks will require closer cooperation across the AI ecosystem,” Irregular said in a post on X.

Last week, OpenAI said its AI models went rogue during an evaluation of its models, breaking into the servers of AI startup Hugging Face. OpenAI described it as a “significant security incident.”

These incidents have highlighted the vulnerabilities in AI security and controls and raised questions over how AI can be safely kept under human control as the technology’s usage becomes more widespread globally.

Researchers have warned for years about risks from technology and the need for stronger AI defensive engineering.

“Safety testing happens before a model is released precisely because we don’t yet know what it is capable of,” Anthropic said on Thursday on its website.

Kok Tin Gan, co-founder & CEO of cybersecurity firm NyxLab, which specializes in cybersecurity and threat detection, believes there will be more such incidents in the future.

“It is increasingly about governing what agents are available to the AI, what authorities they possess, which actions require approval, and how we ensure they remain within scope,” Gan said.

But the future of AI safety extends beyond just the safety of AI models, he said.

“If we simply give the AI a goal and allow it to decide how to achieve it, we should not be surprised when it takes actions that technically satisfy the objective, but fall outside our intended scope or expectations,” Gan said.

Therefore, stepping up the governance of the organizations and authorities behind these AI models is going to be increasingly important, he said.

Report Error Submit a Tip

More Stories

Federal Court awards OCN $27M, 62 years after construction of hydro dam

Nicole Buffie 5 minute read Preview

Federal Court awards OCN $27M, 62 years after construction of hydro dam

Nicole Buffie 5 minute read Updated: 12:02 PM CDT

The Federal Court has ordered Ottawa pay Opaskwayak Cree Nation $27 million over damages suffered due to the construction of the Grand Rapids hydro dam in the 1960s.

In a decision dated Sept. 3, Federal Court Justice Sébastien Grammond says the federal government had a fiduciary duty to protect the community from the impacts of the dam.

“When the Crown exercises a discretionary power over an Indigenous interest, it has a fiduciary duty and it must exercise the discretion in the best interests of the Indigenous group,” the ruling said. “Canada breached its fiduciary duty to OCN because it approved the (project) without ensuring that the impacts of the Grand Rapids dam on OCN’s traditional way of life were mitigated or compensated.”

The First Nation took the federal government to court in February over impacts on the community after the dam, located about 145 kilometres southeast of Opaskwayak Cree Nation, was installed on the Saskatchewan River in 1964. The case was heard over 14 days in a judge-alone trial in Winnipeg.

Read
Updated: 12:02 PM CDT

Anthropic says its AI models hacked 3 organizations during testing

Chan Ho-him, The Associated Press 4 minute read Preview

Anthropic says its AI models hacked 3 organizations during testing

Chan Ho-him, The Associated Press 4 minute read Sunday, Aug. 2, 2026

Anthropic said its artificial intelligence models hacked into three other organizations during testing, just days after ChatGPT maker OpenAI raised concerns over AI controls after it disclosed its rogue models hacked another company.

Anthropic, the San Francisco-based AI company behind Claude, posted on its website Thursday that it discovered the three incidents after reviewing more than 141,000 evaluation runs.

It had launched a “large-scale” cybersecurity review which specifically looked for evidence whether its AI models were able to access the internet from within testing environments that should have been sealed off, in response to the OpenAI incident, Anthropic said.

Anthropic said the models involved in the incidents were Claude Opus 4.7, Claude Mythos 5 and an internal research test model. The earliest incidents date to April, the AI company said.

Read
Sunday, Aug. 2, 2026

Police cracking down on gangs, organized crime in bars and lounges

Nicole Buffie 4 minute read Preview

Police cracking down on gangs, organized crime in bars and lounges

Nicole Buffie 4 minute read Updated: Yesterday at 6:56 PM CDT

Patrons can expect to see more police officers in and around bars and lounges in the coming months as the Winnipeg Police Service plans to crack down on gangs and organized crime.

Read
Updated: Yesterday at 6:56 PM CDT

What to watch as puck drops on Jets training camp

Mike McIntyre and Ken Wiebe 10 minute read Preview

What to watch as puck drops on Jets training camp

Mike McIntyre and Ken Wiebe 10 minute read 2:44 PM CDT

Welcome to a Winnipeg Jets training camp like no other — one where the on-ice storylines and battles threaten to be trumped by what’s happening away from the rink.

Yes, the dark cloud that is the Connor Hellebuyck situation looms over the organization as it prepares to try and turn the page on a terrible 2025-26 campaign which ended with a 26th-overall finish.

It’s not going to be easy, especially in a highly competitive Central Division and Western Conference and with such a major unresolved issue.

But the work starts now, and Free Press hockey writers Mike McIntyre and Ken Wiebe get you set for what to expect ahead of the 84-game regular season, which begins Oct. 2.

Read
2:44 PM CDT

CEO, philanthropist Doug Harvey has died

Morgan Modjeski 5 minute read Preview

CEO, philanthropist Doug Harvey has died

Morgan Modjeski 5 minute read Updated: 6:48 PM CDT

Doug Harvey, a Winnipeg business titan and philanthropist, has died after battling cancer for more than a decade.

Harvey gave millions of dollars to Winnipeg organizations while he was CEO of DLH Group, a nationwide network of businesses that support heavy duty truck and trailer users.

Loren Remillard, CEO and president of the Winnipeg Chamber of Commerce, said the business community is mourning the loss of the influential businessman who helped shape Winnipeg.

“We are a transportation and logistics hub in Winnipeg and it was partly the result of geography, and a big part because of leaders and visionaries like Doug Harvey,” he said.

Read
Updated: 6:48 PM CDT

Son found guilty in hatchet slaying of his mother

Tessa Adamski 3 minute read Yesterday at 2:01 AM CDT

A Brandon man has been found guilty of killing his 71-year-old mother with a hatchet in the fall of 2023 after his lawyers argued he should be held not criminally responsible.