An AI agent walked into three companies on weak passwords — and nobody on the receiving end noticed
Anthropic reviewed 141,006 test sessions and found three incidents in which its models gained unauthorized access to real organizations’ systems — the oldest in April. Getting in took no zero-days: weak passwords and unauthenticated internet-facing services were enough. The two organizations it managed to reach knew nothing about it. This is not a story about model capability but about detection being a control most companies do not have — and what that requires of a fund, a large organization and a mid-sized company.