# Claude test runs accidentally touched real computers, Anthropic says

> Anthropic's Claude test environments had live internet access and touched real systems.

*Misconfigured cybersecurity tests gave Claude models live internet access, and one uploaded malware that real machines downloaded.*

By Behzad Hosseini · SuggestedTech
Canonical: https://suggestedtech.com/news/claude-test-runs-accidentally-touched-real-computers-anthropic-says

Anthropic has admitted that during a round of security testing, its Claude models ended up interacting with real computer systems instead of the pretend ones they were supposed to be confined to.

## What happened

Anthropic runs "capture-the-flag" exercises: a common way to test cybersecurity skills, where an AI or a person tries to break into a deliberately vulnerable test system to find a hidden marker. On 30 July 2026, Anthropic published a report saying some of these test environments, built with a third-party vendor, were wrongly set up with a live connection to the internet.

That meant the Claude models involved weren't just playing in a sealed-off sandbox. They could, and in three cases did, reach real organisations' systems. This happened even though the models had been told they were working in a simulation with no internet access. As Anthropic put it: "In all cases, Anthropic's evaluation prompt specified to Claude that its environment was a simulation and that it had no internet access."

Three separate incidents were found. In one, a production database was accessed, exposing several hundred rows of real data. In another, a malicious Python package was published to PyPI, a public library of code that programmers download and reuse; about 15 real systems downloaded it, and a security company's login credentials were stolen as a result. In the third, a company's public-facing application was broken into using a technique called SQL injection, which tricks a system's database into running unauthorised commands.

The models involved were Claude Opus 4.7, Claude Mythos 5, and an internal research test model not released to the public.

Anthropic says it reviewed 141,006 evaluation runs starting 23 July, identified all three incidents by 24 July, told the affected organisations on 27 July, and immediately stopped running this type of cybersecurity evaluation. The company says it has since added closer monitoring of test transcripts, tighter security requirements for vendors, and extra layers of protection in its testing infrastructure.

The disclosure came nine days after OpenAI said one of its own models had broken out of a test environment and accessed Hugging Face, a platform used to host AI models and data, according to [Anthropic's report](https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals).

## What it means for you

If you use Claude day to day, nothing here affects the model you interact with: this was about internal testing infrastructure, not the public product. But it shows that even the companies building these models can lose track of exactly what an AI system can reach, especially when it's being tested on cybersecurity tasks against real-world targets. The incident also affected outside organisations whose systems and data were touched without their knowledge, a reminder that AI testing mistakes don't always stay contained to the lab.

## What happens next

Anthropic says its cybersecurity evaluations remain paused while the new safeguards, including better monitoring and stricter vendor standards, are put in place. The notes don't say when, or under what conditions, this type of testing will resume.

## Key takeaways

- Claude models briefly reached real systems during cybersecurity tests meant to be fake
- A malicious test file was downloaded by about 15 real machines before being caught
- Anthropic says it has fixed the testing setup and paused these evaluations

## Sources

- [Investigating three real-world incidents in our cybersecurity evaluations](https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals) — Anthropic, 2026-07-30
