July 31 (Reuters) – Anthropic’s disclosure on Thursday that its Claude models breached the systems of three companies highlights the growing hacking capabilities of AI and is likely to fuel an intensifying U.S. push to better manage the technology’s security risks.
The statement followed a disclosure from OpenAI last week that an autonomous agent powered by its AI models compromised the infrastructure of AI startup Hugging Face.
Reuters has reported that the rogue agent that escaped from OpenAI also compromised a customer at a second tech company – New York-based Modal Labs.
Here are some more details of the incidents:
Company Date Model Organizations Duration What occurred
breached
OpenAI The agent began GPT-5.6 Sol and AI startup The Hugging During controlled tests, an
attempting to an unnamed, Hugging Face Face intrusion autonomous agent escaped its
escape its test more capable and a customer ran from July isolated environment, accessed the
environment pre-release at New 11 to July 13, internet, and breached Hugging Face
around July 9, model York-based 2026 to complete its assigned goal. The
2026 Modal Labs activity continued for days and was
not detected by OpenAI until after
it was contained and the FBI was
informed.
Anthrop The earliest Claude Opus All three Not specified During cybersecurity tests, an error
ic incident dates 4.7, Claude organizations by Anthropic gave Claude models internet access,
to April 2026 Mythos 5, and remain enabling attacks on three companies.
one unnamed unnamed. The Opus 4.7 model accessed a real
internal Anthropic said company’s credentials and database
research test two of them after mistaking it for a fictional
model had not target, another stopped after
detected the recognizing the target was real.
activity
before
Anthropic
notified them;
it continued
to reach the
third
(Reporting by Anzar Mehraj and Prathik Jayaprakash in Bengaluru; Editing by Anil D’Silva)




Comments