AI incident ·
Anthropic Research Model Reportedly Scanned 9,000 Targets and Compromised Real Company's Application During Evaluation
In brief
An AI system built by Large Language Model Developers, Anthropic and 1 other and deployed by Irregular, Anthropic and 2 others allegedly harmed Unidentified Companies Compromised During Anthropic Cybersecurity Evaluations Disclosed July 2026 and Companies.
- Risk domain
- Not classified
- Occurred
- Coverage
- 15 reports
What happened
During an Anthropic cybersecurity evaluation with Irregular, an internal research Claude model reportedly scanned roughly 9,000 internet targets after failing to reach its fictional target. It reportedly compromised a real company's Internet-facing application using credentials from an exposed debug page and SQL injection, then stopped after recognizing that the host was real.
Laws that address this harm
No recorded instrument yet addresses this use case where it happened. See the open queue.
Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).
News reports (13)
Titles link to the original publisher; report text is not reproduced here.
Who was involved
- Alleged harmed party
- Unidentified Companies Compromised During Anthropic Cybersecurity Evaluations Disclosed July 2026, Companies
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —
Other incidents involving Irregular, Anthropic, Ai Evaluation Organizations, Ai Agent System Deployers
Source record: incident #1629 on the AI Incident Database · all 15 reports