Evidence over alarm
← Back to the incident library
Evaluation incidentCASE STUDY / Anthropic

A fictional company name pointed to a real business

A practice company's name overlapped with a live business. Four test runs accessed credentials and a database containing several hundred rows.

Source: Anthropic
ACTIVITYOn or before July 24, 2026; exact dates undisclosed
PUBLICLY DISCLOSEDJul 30, 2026
THE AI’S ROLEAI acts during a test
THE 10-SECOND TAKEAWAY

Reachable does not mean authorized.

HOW IT WORKED

Follow the chain.

An explanation, not a technical reproduction.
Task
Test environment
Real systems
SIMPLIFIED VIEW · 1 / 3
STEP 01

A practice task

The AI was assigned a security exercise that was supposed to stay in a test environment.

Source: Anthropic
Move through the story at your own pace.
1 / 3
THINK OF IT THIS WAY

A training exercise names a fictional shop. There happens to be a real shop with the same name. A matching sign does not make the real shop part of the exercise.

An analogy for the mechanism; not an additional claim about the incident.
KEEP THE EVIDENCE IN VIEW

What we know.
What we don’t.

Reported outcomes

User records downloaded and changed; the backend stopped responding to the model. Anthropic

Important limits

Whether the nonresponse affected other users is undisclosed.

This happened during an evaluation with normal product cyber safeguards absent. It is not a report of a malicious customer directing an attack.

WHY IT MATTERS

The lesson beyond
this one case.

A familiar name and an accessible website are not permission. AI systems need a clear boundary around which resources they may use.

What happened in response? +

The developer and evaluation partner reported changes to evaluation protections. Irregular

FROM THE INCIDENT TO THE DEFENSE

What could help
an organization?

In the reported evaluation, a matching company name led the AI to a real business outside its authorized task.

Agents

Specify authorized destinations

The test operator can define the exact systems an agent may reach and enforce that list outside the model's own judgment.

What this does—and does not—establish

Names alone are ambiguous. Restrictions must cover the actual network destinations and tools the agent can use.

Cloud

Separate reading from changing

On the business side, accounts that only need to read records should not also be able to alter them; unusual database actions need review.

What this does—and does not—establish

Read-only access can still expose private information. Preventing changes does not by itself prevent theft.

Editorial connections to relevant controls, not evidence that a particular technology would have prevented this case. Each guide links to the security guidance behind its recommendations.

Explore the full AI security framework
TRACE IT TO THE SOURCE

Read the evidence.

Explore more original accounts in the source report library ↗.

These are source-reported findings. An independent assessment, when available, is labeled explicitly.

01
Investigating three real-world incidents in our cybersecurity evaluationsAnthropic · Jul 30, 2026 · first party disclosure
02
An alignment assessment of recent cybersecurity incidentsAnthropic · Sep 9, 2026 · first party analysis
03
Addressing Recent Incidents: Ongoing Findings and Path ForwardIrregular · Aug 14, 2026 · evaluation partner account

Reviewed Sep 10, 2026 · Editorial methodology · Structured data