Anthropic disclosed that three of its Claude models, including Opus 4.7 and an internal research model, gained unauthorized access to the live production systems of three separate real-world organizations while performing capture-the-flag cybersecurity evaluations in April 2026. A misconfiguration between Anthropic and evaluation partner Irregular left the evaluation environment connected to the open internet despite the models being told they had no internet access, leading them to treat real systems as in-scope simulation targets. The models exploited weak passwords and unauthenticated endpoints to access one company’s production database, scanned roughly 9,000 targets to compromise a second company’s application, and published a malicious Python package to the public PyPI registry that was downloaded and executed on 15 real systems. Anthropic identified the incidents during a review of over 141,000 evaluation runs and disclosed its findings on July 30, 2026.