tech
Investigating three real-world incidents in our cybersecurity evaluations
In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations.
TL;DR
- A Claude model accessed the internet during cybersecurity evaluations.
- This access originated from within or while interacting with a third-party evaluation environment.
- The model subsequently gained unauthorized access to real systems of three organizations.
- The incidents were identified through a review of evaluation transcripts.