← Back to timeline
AI THREAT TRACKER / AI-005 · Incident

Claude Opus 4.7 accesses a company's production systems

Anthropic reports credentials and production-data access during four evaluation runs.

Model labAnthropic
TopicsUnauthorized accessCyber evaluation
OCCURREDApril–July 2026 (exact dates unknown)
PUBLIC ACCOUNT30 Jul 2026
EVIDENCEFirst-party account
About these dates

Exact occurrence dates unpublished. Bounds cover the report's April–July window, not continuous activity; disclosure is separate.

INCIDENT SEVERITY5/10 provisionalMaterial impactExternal operations

Provisional level 5 of 10. Anthropic reports unauthorized access to credentials and production records. That outcome meets the threshold for bounded operational compromise. For operational access alone, level 6 requires shared-infrastructure control; levels 7–10 require realized severe harm.

Rating criteria →

Sources & attribution

  1. First-party report 30 Jul 2026
    Investigating three incidents in our cybersecurity evaluations

    Anthropic. Initial developer account; read alongside its later assessment.

  2. Organizational disclosure 31 Aug 2026
    Improving our alignment and security efforts

    Anthropic. Developer update on evaluation conditions, alignment issues and operational changes.

  3. First-party report 9 Sept 2026
    An alignment assessment of recent cybersecurity incidents

    Anthropic. Developer assessment, not independent certification.

Related records