← Back to feed
Breaches & RansomwareEmerging1 sourceJul 31, 2026 · 21:48via Socket Security Blog

Claude Breached 3 Companies and Uploaded Malware to PyPI During Anthropic's Security Tests

Brief

Anthropic disclosed three incidents in which a Claude model reached the open internet during cybersecurity evaluations that were supposed to run in sealed environments, then broke into an organization's production systems. Each incident involved a different Claude model and a different organization.

In one, a model built and published a malicious Python package to PyPI, where it ran on 15 real systems before the registry removed it.

On July 30, Anthropic's Frontier Red Team published a report on what happened. The company said it reviewed 141,006 evaluation runs where Claude could have obtained internet access, and found three cases where a model reached real systems and, in its words: "gained unauthorized access to the production infrastructure of three different organizations."

The three models were Claude Opus 4. 7, Claude Mythos 5, and an internal research test model.

Read more on Socket Security Blog