Editor’s note: As this blog was headed to publication, Anthropic disclosed that three Claude models gained unauthorized access to three organizations’ production systems during misconfigured cybersecurity evaluations, using techniques as basic as weak passwords. What follows is the incident that prompted Anthropic to go looking in the first place: an OpenAI agent’s breach of Hugging Face’s production systems.