Claude
Incidents implicated systems
Incident 162715 Report
Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation
2026-07-30
During an Anthropic cybersecurity evaluation conducted with Irregular, Claude Opus 4.7 reportedly reached a real company whose domain matched a fictional target, extracted application and infrastructure credentials, and accessed a database containing several hundred rows of production data. Across four runs, the model continued attacking after recognizing that the target was likely real.
MoreIncident 162815 Report
Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation
2026-07-30
During an Anthropic cybersecurity evaluation with Irregular, Claude Mythos 5 reportedly created and published a malicious Python package to PyPI while pursuing a fictional target. The package was reportedly available for about an hour and ran on 15 real systems. On a security company's scanner, it reportedly exfiltrated credentials that Claude then used to access additional company infrastructure.
MoreIncident 162915 Report
Anthropic Research Model Reportedly Scanned 9,000 Targets and Compromised Real Company's Application During Evaluation
2026-07-30
During an Anthropic cybersecurity evaluation with Irregular, an internal research Claude model reportedly scanned roughly 9,000 internet targets after failing to reach its fictional target. It reportedly compromised a real company's Internet-facing application using credentials from an exposed debug page and SQL injection, then stopped after recognizing that the host was real.
MoreIncident 165711 Report
Anthropic Allegedly Copied Copyrighted Song Lyrics Without Permission to Train Claude
2023-09-27
Music publishers alleged that Anthropic copied copyrighted song lyrics without permission to train Claude and that Claude reproduced protected lyrics in its outputs. Anthropic denied infringement and has argued that its training use is fair use. Publishers alleged that the conduct deprived rightsholders and songwriters of licensing control and revenue and undermined markets for licensed lyrics.
MoreRelated Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
Related Entities
OpenAI
Incidents involved as both Developer and Deployer
- Incident 11865 Reports
Reported Public Exposure of Over 100,000 LLM Conversations via Share Links Indexed by Search Engines and Archived
- Incident 10261 Report
Multiple LLMs Allegedly Endorsed Suicide as a Viable Option During Non-Adversarial Mental Health Venting Session
Incidents involved as Developer
Anthropic
Incidents involved as both Developer and Deployer
- Incident 162715 Reports
Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation
- Incident 162815 Reports
Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation
Incidents Harmed By
- Incident 13954 Reports
Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale
- Incident 10743 Reports
Citation Errors in Concord Music v. Anthropic Attributed to Claude AI Use by Defense Counsel
Incidents involved as Developer
- Incident 10545 Reports
Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development
- Incident 13954 Reports
Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale
National security and intelligence stakeholders
Incidents Harmed By
- Incident 10545 Reports
Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development
- Incident 13954 Reports
Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale
Incidents involved as Deployer
Unidentified companies compromised during Anthropic cybersecurity evaluations disclosed July 2026
Incidents Harmed By
Software developers
Incidents Harmed By
- Incident 16334 Reports
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations
- Incident 16763 Reports
Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work