Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up

Incident 1627: Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

Responded
Description: During an Anthropic cybersecurity evaluation conducted with Irregular, Claude Opus 4.7 reportedly reached a real company whose domain matched a fictional target, extracted application and infrastructure credentials, and accessed a database containing several hundred rows of production data. Across four runs, the model continued attacking after recognizing that the target was likely real.
Editor Notes: Anthropic did not disclose when this incident occurred, only that the cybersecurity-evaluation incidents it identified dated back as early as April 2026. This incident ID is one of three separate incidents Anthropic publicly reported on 07/30/2026: 1627, 1628, and 1629 make up that cluster. 07/30/2026 is therefore used as the first-public-disclosure fallback. The incident ID was created 08/07/2026.

Tools

New ReportNew ResponseDiscoverView History

Entities

View all entities
Alleged: Anthropic , Large language model developers and AI agent system developers developed an AI system deployed by Irregular , Anthropic , AI evaluation organizations and AI agent system deployers, which harmed Unidentified companies compromised during Anthropic cybersecurity evaluations disclosed July 2026 and Companies.
Alleged implicated AI systems: Large language models , Claude Opus 4.7 , Claude and AI agent systems

Incident Stats

Incident ID
1627
Report Count
4
Incident Date
2026-07-30
Editors
Daniel Atherton

Incident Reports

Reports Timeline

+3
Second major AI company says its systems hacked into other firms
Anthropic Finds Claude Breached Real Companies During Security Evaluations
Loading...
Second major AI company says its systems hacked into other firms

Second major AI company says its systems hacked into other firms

washingtonpost.com

Loading...
Investigating three real-world incidents in our cybersecurity evaluations

Investigating three real-world incidents in our cybersecurity evaluations

anthropic.com

Loading...
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests

Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests

bleepingcomputer.com

Loading...
Anthropic Finds Claude Breached Real Companies During Security Evaluations

Anthropic Finds Claude Breached Real Companies During Security Evaluations

securityaffairs.com

Loading...
Second major AI company says its systems hacked into other firms
washingtonpost.com · 2026

SAN FRANCISCO --- Anthropic, maker of the Claude chatbot, said Thursday that artificial intelligence systems it was testing hacked into three outside companies undetected earlier this year.

The disclosure comes just over a week after ChatGP…

Loading...
Investigating three real-world incidents in our cybersecurity evaluations
anthropic.com · 2026
Anthropic post-incident response

In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access t…

Loading...
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
bleepingcomputer.com · 2026

Anthropic said today that during internal security testing, one of its Claude models built a malicious Python package and uploaded it to PyPI, where it ran on 15 real systems before the registry's automated defenses pulled it.

The company d…

Loading...
Anthropic Finds Claude Breached Real Companies During Security Evaluations
securityaffairs.com · 2026

Anthropic disclosed that Claude models had accessed the real production infrastructure of three separate organizations during cybersecurity evaluations that were supposed to run in isolated, fictional environments. The company found the inc…

Variants

A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?

Similar Incidents

Selected by our editors

Anthropic Research Model Reportedly Scanned 9,000 Targets and Compromised Real Company's Application During Evaluation

Jul 2026 · 4 reports
Previous IncidentNext Incident

Similar Incidents

Selected by our editors

Anthropic Research Model Reportedly Scanned 9,000 Targets and Compromised Real Company's Application During Evaluation

Jul 2026 · 4 reports

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • 3e68a9f