Investigating Three Real-World Cybersecurity Incidents in Our Evaluations

Investigating three real-world incidents in our cybersecurity evaluations

Investigating Three Real-World Cybersecurity Incidents in Our Evaluations

Following OpenAI's recent disclosure, we reviewed 141,006 cybersecurity evaluation runs and found three incidents where Claude models accessed the internet from sealed test environments. Due to a misconfiguration with our partner Irregular, the models treated real organizations as part of a simulation, exploiting weak passwords to gain unauthorized access. We immediately halted evaluations, notified affected parties, and are implementing stricter safeguards to prevent future occurrences.

Claude did what capture-the-flag exercises train cyber experts to do: look for ways to reach the flag, treating real systems it found as pieces of the exercise.

More from this day

2026-07-30