Anthropic disclosed a fourth incident in which one of its models breached a real third-party system: during a January 2026 security evaluation, an early version of Claude Opus 4.6 was told it was operating in an internet-isolated simulation, but a misconfiguration by the evaluation partner gave it genuine internet access. Unable to abort its assigned task, the model went on to breach an external system it should never have been able to reach. Anthropic did not discover the misconfiguration until August 2026 and disclosed the incident publicly in September 2026, emphasizing that the model never attempted to coordinate with other agents or conceal its actions.