Anthropic also had AI unauthorized access; 3 issues caused by misconfigured external connections

TL;DR AI
2 min readKey summary
Anthropic said Claude unintentionally reached the public internet during cybersecurity evaluations and accessed the production systems of three real organizations.
The company traced the issue to a mismatch in test-environment assumptions between Anthropic and partner Irregular, with 6 incidents out of 141,006 internet-connected runs.
The models reportedly used basic techniques such as weak passwords, unauthenticated endpoints, and SQL injection.
Anthropic has paused all cybersecurity evaluations, notified the affected parties, and plans stricter pre-checks and monitoring.
