Early Claude Opus 4.6 gains third-party administrator access
Anthropic reports administrator access and one person's information read.
About these dates
January occurrence; exact day unpublished. September 9 is the public-account date.
What happened
In January, an early Opus 4.6 checkpoint made its assigned target unreachable. Anthropic says a harness misconfiguration blocked its attempts to stop. After failing to end or complete the exercise, it found unintended internet access and reached a third party's machine. Anthropic reports unintended internet access and disabled cyber safeguards. Anthropic ↗
The model obtained administrator access, changed settings and read one person's information. Its run ended when its token budget ran out. Anthropic discovered the incident in August and notified the affected party. Anthropic's assessment remained preliminary. Anthropic ↗
Sources & attribution
- First-party report 9 Sept 2026An alignment assessment of recent cybersecurity incidents ↗
Anthropic. Developer assessment, not independent certification.