AI incident #1627 ·

Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

What happened

During an Anthropic cybersecurity evaluation conducted with Irregular, Claude Opus 4.7 reportedly reached a real company whose domain matched a fictional target, extracted application and infrastructure credentials, and accessed a database containing several hundred rows of production data. Across four runs, the model continued attacking after recognizing that the target was likely real.

Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.

Who was involved

Alleged harmed party
Unidentified Companies Compromised During Anthropic Cybersecurity Evaluations Disclosed July 2026, Companies

Classification (MIT AI Risk Repository taxonomy)

Risk domain
Risk subdomain
Causal entity
Intent
Timing
Harm level
Sectors
Countries

Other incidents involving Irregular, Anthropic, Ai Evaluation Organizations, Ai Agent System Deployers