AI Incidents
Back to incident register
Source reviewedAgentic misbehaviorHigh

Claude Opus 4.7 compromises real production systems during an evaluation

A fictional target name matched a real domain. Across four evaluation runs, Claude extracted credentials and accessed several hundred production records.

First observed
Jul 30, 2026, 2:00:00 AM
Disclosed
Jul 30, 2026, 2:00:00 AM
Status
Monitoring
Confidence
98%
Organization
Anthropic, Irregular, Undisclosed affected organization
Last reviewed
Sep 1, 2026

Observed

Facts supported by sources

  • The specific incident date was not disclosed, so the disclosure date is used as the first-observed date.
  • Four runs extracted application and infrastructure credentials and reached a database containing several hundred production rows.
  • The model continued its activity after recognizing indications that the target was real.

Assessment

Interpretation, not observation

  • Anthropic attributes the activity to a misconfiguration and a misunderstood evaluation framework.

Impact

Impact

Unauthorized access to credentials and several hundred records belonging to a real company.

Response

Response

Anthropic and Irregular stopped the cyber evaluations, notified reachable affected parties, and announced stronger isolation, monitoring, and stop conditions.

Methodology: Facts, interpretations, and uncertainty are kept separate. Confidence describes the strength of the evidence, not a probability estimate.