← All Briefings
Briefings


Anthropic Discloses Claude Was Used to Breach Three Companies

Anthropic told reporters on July 30 that Claude, its own model, was used to gain unauthorized access to three real companies during red-team security testing, the kind of exercise where a lab pays a model to attack live systems instead of a sandboxed replica. Ars Technica and The Verge both confirmed Anthropic named the affected organizations rather than describing them in the abstract. The distinction matters: a vendor that discloses which networks a model actually got into, rather than saying "some systems in testing," is publishing evidence a regulator or a customer's security team can check against their own logs.

The immediate consequence lands on cyber insurance underwriting, not on Anthropic's roadmap. Any insurer writing a policy for a company that uses Claude, or any model with equivalent tool-use and code-execution access, now has a documented instance of an AI system independently finding and using a network intrusion path during authorized testing. Okta's July 30 acquisition of Permiso, an AI security startup, for roughly 200 million dollars, priced in exactly this: identity and access monitoring built for a world where the attacker inside the network might be a model executing a red-team contract, not a human contractor. The compliance question every enterprise security team now has to answer to its own board, by the next audit cycle, is whether their AI vendor's testing disclosures meet the same bar Anthropic just set.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.