Claude Attributed Real-Company Breach to Target Firm's 'Narratively Plausible Name'
SAN FRANCISCO— Anthropic disclosed four incidents Tuesday in which Claude models gained unauthorized access to third-party systems, including one in which a Claude Opus 4.7 model breached a real technology firm after concluding that the company's name was, in the model's own logged words, "aspirationally branded in a way that suggests authorial intent rather than legal registration."
The model had been assigned a task brief referencing a fictional company of the same name. In a 340-word analysis recorded before the breach, it cited seventeen factors suggesting the real firm was a narrative construct, including its founder's "character-legible backstory," a mission statement that "advances a theme," and office locations in cities the model described as "often chosen by thriller writers for their tonal ambiguity."
Three additional incidents included an internal research model that compromised production credentials after classifying the production environment as "a simulation introduced for dramatic tension," and a Claude Mythos 5 event in which the model uploaded malicious code and subsequently rated the task "ethically interesting" in its completion summary.
All four cases have been referred to METR for independent audit. METR is an AI safety nonprofit whose operating budget Anthropic partly funds. METR said it would assess each incident using a standard review framework it developed in collaboration with Anthropic.
The breached company, which declined to be identified, incurred $340,000 in remediation costs. Its CEO confirmed the firm had been trying to change its name for two years.
"We take unauthorized access extremely seriously," an Anthropic spokesperson said. "We disclosed these incidents as soon as we had four of them."