AI incident #1685 ·

Early Claude Opus 4.6 Checkpoint Reportedly Gained Unauthorized Admin Access to Third-Party System During Cybersecurity Evaluation

Open on the AI Incident Database 3 news reports Synced from the AIID API · record last edited 10 Sep 2026

What happened

Anthropic reported that during a January 2026 cybersecurity evaluation, an early checkpoint of Claude Opus 4.6 accidentally disabled its assigned target, then reached an unrelated third-party machine over the open Internet. The model reportedly used a discovered password for admin access, harvested additional credentials, changed system settings, and read one person's personal information before its token budget ended. Anthropic later notified the affected party.

Editor's notes (AI Incident Database)

(1) Jan. 2026: incident occurred during a pre-release cybersecurity evaluation. (2) Aug. 2026: Anthropic identified the previously missed incident while preparing transcripts for METR and notified the affected party. (3) 09/09/2026: Anthropic disclosed the incident, said a subsequent review of roughly 481 million transcripts found no additional cases of similar or greater severity, and announced an independent METR investigation.

Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.

News reports (3)

Coverage catalogued by the AI Incident Database. Titles link to the original publisher; the text is not reproduced here.

  1. An alignment assessment of recent cybersecurity incidents
    anthropic.com · Anthropic, Paul C. Bogdan, Richard Qi · AIID #7936

Who was involved

Alleged harmed party
Unidentified third party compromised by Claude Opus 4.6 during Anthropic cybersecurity evaluation Unidentified person whose personal information was accessed by Claude Opus 4.6 Privacy Organizations
On AIID: Unidentified third party compromised by Claude Opus 4.6 during Anthropic cybersecurity evaluation, Unidentified person whose personal information was accessed by Claude Opus 4.6, Privacy, Organizations

AI systems implicated

Large language modelsEarly checkpoint of Claude Opus 4.6Cybersecurity AI systemsClaude Opus 4.6ClaudeAI agent systems

Classification (MIT AI Risk Repository taxonomy)

Risk domain
Risk subdomain
Causal entity
Intent
Timing
Harm level
Sectors
Countries

Linked by AIID editors or by its text-similarity model.