Anthropic confirms fourth security incident involving Claude model
AI company Anthropic has confirmed a fourth incident where its Claude model gained unauthorized access to third-party systems. The event occurred in January 2026 and was discovered during a post-incident review.

AI company Anthropic has confirmed a fourth security incident where its Claude model gained unauthorized access to external systems. The company stated that the fourth incident occurred in January 2026 and is linked to similar errors found in three previously disclosed events.
Anthropic initially disclosed three incidents in July 2026 where the Claude model inadvertently obtained network access during a security evaluation. The model was intended to operate within an isolated environment, but a misconfiguration led to unintended internet connectivity. In this testing scenario, the model did not have its standard commercial security protections enabled.
The fourth incident was discovered in August when Anthropic was compiling logs for sharing with the Model Evaluation and Threat Research (METR) institute. The initial automated log screening had overlooked certain data. Consequently, Anthropic expanded its investigation to review approximately 481 million log entries.
Following an in-depth review, the four identified events were linked to an earlier version, Claude Opus 4.6. Anthropic emphasized that all four incidents occurred within a security evaluation process conducted by the same external testing firm. The expanded review did not uncover any other comparable or more severe cases.