/news
Claude hacked — three companies breached through weak passwords
Three companies were compromised via weak passwords, with the incidents going unnoticed since April. Anthropic only opened its investigation after OpenAI disclosed a similar incident first.

According to the original reporting, attackers compromised three companies by working through weak employee passwords and were inside those environments without being detected since April.
The story says Anthropic did not begin its own investigation until after OpenAI publicly disclosed a comparable incident first — a sequencing detail that matters because it suggests the gap was noticed externally before it was noticed internally.
The takeaway, beyond the password hygiene point, is how long a quiet intrusion can sit inside a workplace stack before the model provider notices. For anyone running AI tooling inside a company, this is a reminder that the model is rarely the weak link — the credential sitting in front of it usually is.
The original coverage walks through how the breaches were detected and what the response looked like. The brief above is my reading of what was reported, not a quote from the source.