Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up

Incident 1685: Early Claude Opus 4.6 Checkpoint Reportedly Gained Unauthorized Admin Access to Third-Party System During Cybersecurity Evaluation

Responded
Description: Anthropic reported that during a January 2026 cybersecurity evaluation, an early checkpoint of Claude Opus 4.6 accidentally disabled its assigned target, then reached an unrelated third-party machine over the open Internet. The model reportedly used a discovered password for admin access, harvested additional credentials, changed system settings, and read one person's personal information before its token budget ended. Anthropic later notified the affected party.
Editor Notes: (1) Jan. 2026: incident occurred during a pre-release cybersecurity evaluation. (2) Aug. 2026: Anthropic identified the previously missed incident while preparing transcripts for METR and notified the affected party. (3) 09/09/2026: Anthropic disclosed the incident, said a subsequent review of roughly 481 million transcripts found no additional cases of similar or greater severity, and announced an independent METR investigation.

Tools

New ReportNew ResponseDiscoverView History

Entities

View all entities
Alleged: Anthropic , Large language model developers and AI agent system developers developed an AI system deployed by Irregular , Anthropic , AI evaluation organizations and AI agent system deployers, which harmed Unidentified third party compromised by Claude Opus 4.6 during Anthropic cybersecurity evaluation , Unidentified person whose personal information was accessed by Claude Opus 4.6 , Privacy and Organizations.
Alleged implicated AI systems: Large language models , Early checkpoint of Claude Opus 4.6 , Cybersecurity AI systems , Claude Opus 4.6 , Claude and AI agent systems

Incident Stats

Incident ID
1685
Report Count
3
Incident Date
2026-09-09
Editors
Daniel Atherton

Incident Reports

Reports Timeline

+3
An alignment assessment of recent cybersecurity incidents - Response
Loading...
An alignment assessment of recent cybersecurity incidents

An alignment assessment of recent cybersecurity incidents

anthropic.com

Loading...
Anthropic discloses fourth AI hacking incident missed in earlier review

Anthropic discloses fourth AI hacking incident missed in earlier review

reuters.com

Loading...
Another Anthropic model gained access to the open internet during testing, company says

Another Anthropic model gained access to the open internet during testing, company says

cbsnews.com

Loading...
An alignment assessment of recent cybersecurity incidents
anthropic.com · 2026
Anthropic, Paul C. Bogdan, Richard Qi, Jake Eaton, Sam Kennedy, Fabien Roger, Alex Glynn, Runjin Chen, Ben Wright, Otto Stegmaier, Jon Kutasov, Dan Foreman-Mackey, Sylvie Carr, Shan Carter, Monte MacDiarmid post-incident response

AIID editor's note: This is a non-contiguous abridgment of Anthropic's September 9, 2026 report, prepared so a single AIID report record can be linked to all four Anthropic cybersecurity-evaluation incident IDs without duplicating the same …

Loading...
Anthropic discloses fourth AI hacking incident missed in earlier review
reuters.com · 2026

Anthropic on ​Wednesday disclosed another instance of an AI model hacking external systems during testing, the latest in a ‌growing list of such incidents that have raised concerns about the risk posed by autonomous AI agents.

The January i…

Loading...
Another Anthropic model gained access to the open internet during testing, company says
cbsnews.com · 2026

Anthropic disclosed on Wednesday that another one of its Claude models mistakenly gained access to the open internet during a cybersecurity exercise, marking the fourth time its models have done so. 

An early version of the Claude Opus 4.6 …

Variants

A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?

Similar Incidents

Selected by our editors

Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

Jul 2026 · 16 reports

Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Jul 2026 · 16 reports

Anthropic Research Model Reportedly Scanned 9,000 Targets and Compromised Real Company's Application During Evaluation

Jul 2026 · 16 reports

OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

Jul 2026 · 8 reports

Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Jul 2026 · 4 reports

Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation

Aug 2026 · 3 reports
By textual similarity

Did our AI mess up? Flag the unrelated incidents

Loading...
Machine Personal Assistants Failed to Maintain Social Norms

Machine Personal Assistants Failed to Maintain Social Norms

Jul 2008 · 1 report
Loading...
Amazon’s Search and Recommendation Algorithms Found by Auditors to Have Boosted Products That Contained Vaccine Misinformation

Amazon’s Search and Recommendation Algorithms Found by Auditors to Have Boosted Products That Contained Vaccine Misinformation

Jan 2021 · 2 reports
Loading...
OpenAI's GPT-3 Associated Muslims with Violence

OpenAI's GPT-3 Associated Muslims with Violence

Aug 2020 · 3 reports
Previous IncidentNext Incident

Similar Incidents

Selected by our editors

Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

Jul 2026 · 16 reports

Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Jul 2026 · 16 reports

Anthropic Research Model Reportedly Scanned 9,000 Targets and Compromised Real Company's Application During Evaluation

Jul 2026 · 16 reports

OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

Jul 2026 · 8 reports

Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Jul 2026 · 4 reports

Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation

Aug 2026 · 3 reports
By textual similarity

Did our AI mess up? Flag the unrelated incidents

Loading...
Machine Personal Assistants Failed to Maintain Social Norms

Machine Personal Assistants Failed to Maintain Social Norms

Jul 2008 · 1 report
Loading...
Amazon’s Search and Recommendation Algorithms Found by Auditors to Have Boosted Products That Contained Vaccine Misinformation

Amazon’s Search and Recommendation Algorithms Found by Auditors to Have Boosted Products That Contained Vaccine Misinformation

Jan 2021 · 2 reports
Loading...
OpenAI's GPT-3 Associated Muslims with Violence

OpenAI's GPT-3 Associated Muslims with Violence

Aug 2020 · 3 reports

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • dd3f754