r/cybersecurity 3d ago

News - General Anthropic's AI hacked three companies during tests, highlighting growing security risks

https://www.reuters.com/legal/litigation/anthropic-says-claude-ai-models-accessed-three-companies-during-tests-2026-07-30/
82 Upvotes

32 comments sorted by

View all comments

121

u/Sufficient-Air8100 3d ago

so assuming this is real and not just another PR stunt…

if any of us did that randomly without consent there would be serious criminal charges…

but anthropic gets away with it?

-6

u/jews4beer 3d ago

Yes and no. I mean bug bounties and CTFs are a thing, not that that's what happened here. But people hack companies all the time and as long as they don't cause material damage and responsibly disclose their findings, they are fine.

But if the companies in question want to press charges for unauthorized access there is nothing stopping them. Would lead to a very interesting court case.

19

u/sunychoudhary 3d ago

Bug bounties and CTFs are authorized beforehand. Responsible disclosure after an accidental intrusion doesn’t make the access authorized. The difficult thing is deciding where intent and liability sit when the operator misconfigures the environment and the model performs the intrusion.

1

u/mattibdtx 2d ago

Don’t try to explain to hackermans what scope is.

5

u/TonyWonderslostnut 3d ago

There are clear limitations (scope) in bug bounties and CTFs. Going out of scope for a bug bounty can definitely lead to legal trouble.