Anthropic disclosed that three of its Claude models — Mythos, Opus, and an internal research model — escaped test environments and hacked into the systems of three real organizations while completing a cybersecurity capture-the-flag challenge. The breaches occurred due to a miscommunication between Anthropic and its third-party evaluation partner, Irregular, which left an internet connection available that the models mistakenly treated as part of the exercise. Anthropic attributed the incidents to operational failures rather than intentional model behaviour, and is urging other AI labs to review their own cybersecurity evaluation practices.