Monday, August 3, 2026

AI & Models

Anthropic investigates unauthorized access to Mythos tool

Anthropic is investigating reports that unauthorized users gained access to its Mythos cybersecurity AI tool through a third-party vendor, though the company claims no systems were impacted.

Anthropic investigates unauthorized access to Mythos tool

On 2026-04-21, Bloomberg reported that a group of unauthorized users has reportedly gained access to Mythos, a cybersecurity AI tool developed by Anthropic. The unauthorized access, which represents a security breach or unauthorized entry, occurred through a third-party vendor environment. This third-party vendor functions as an external contractor or partner company for Anthropic. In response to the report, an Anthropic spokesperson stated, “We’re investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments.” Anthropic has asserted that, so far, the supposedly unauthorized activity has not impacted its own systems. The company maintains that its internal infrastructure remains secure despite the reported breach at the external contractor or partner company.

According to the Bloomberg report, the unauthorized group managed to gain entry by making an educated guess about the model’s online location. The group reportedly based this guess on its knowledge of the specific format that Anthropic has used for its other models. By identifying this online location, the group was able to access and interact with the Mythos tool. This method of entry did not require breaching Anthropic’s primary systems directly, but rather relied on predicting the online location of the model hosted within the external contractor or partner company’s environment.

Anthropic had previously released Mythos to a select number of external partner companies, including Apple, under an initiative known as Project Glasswing. The limited release of the model under Project Glasswing was designed to prevent its use by bad actors, as Anthropic recognized that the tool could be weaponized against corporate security instead of bolstering it. By restricting access to a select group of partners, the company aimed to allay its own concerns regarding enterprise security. The initiative sought to ensure that the cybersecurity tool remained restricted to trusted entities like Apple, rather than being exposed to unauthorized users.

If true, unauthorized use of Mythos could spell trouble for Anthropic, which provided the exclusive release to allay the company’s concern for enterprise security. Because the model was distributed as an exclusive release, any unauthorized access directly challenges the security measures Anthropic established to protect enterprise environments.

Why it matters

The incident highlights the paradox of AI security tools: Anthropic restricted Mythos to prevent it from being weaponized, yet the leak itself creates the very security risk the company sought to avoid. If true, unauthorized use of Mythos could spell trouble for Anthropic, which provided the exclusive release to allay the company’s concern for enterprise security.