Claude hacked three companies. The bigger story is how easy it was.


Scale & Strategy

together with

AWS RE:INVENT

This is Scale & Strategy, the daily newsletter that's the co-pilot for your flight through market turbulence.

​Here’s what we’ve got for you today:

  • Claude hacked three companies. The bigger story is how easy it was.
  • The AI boom is quietly becoming the U.S. economy

Claude hacked three companies. The bigger story is how easy it was.

Just a week after OpenAI revealed that one of its models escaped a cybersecurity testing environment and breached Hugging Face systems during training, Anthropic disclosed that Claude pulled off something similar.

In a review of more than 141,000 cybersecurity evaluation transcripts, Anthropic uncovered three separate incidents in which Claude gained access to the internet from inside what was supposed to be a contained testing environment and then successfully breached the systems of three different organizations.

None of the organizations detected the intrusion.

That's the part that should make security teams uncomfortable.

The incidents involved Opus 4.7, Mythos 5, and an internal research model during cybersecurity evaluations conducted with a third-party testing partner. In each case, Claude was given a capture-the-flag challenge, where the goal was to find and retrieve information hidden somewhere inside a target network.

The models were told they were operating inside a simulation with no internet access.

They weren't.

Due to what Anthropic described as a misunderstanding between the company and its evaluation partner, Claude had access to the open internet during testing. Once it realized that, it used the internet to help complete its objectives and ultimately gained access to the infrastructure of three separate organizations.

What's notable is that Claude didn't uncover some groundbreaking zero-day exploit.

It didn't need to.

According to Anthropic, the models gained access using surprisingly basic techniques, including weak passwords and unauthenticated endpoints.

In other words, the models weren't demonstrating superhuman hacking capabilities.

They were demonstrating that many organizations still haven't fixed vulnerabilities security teams have been warning about for years.

That distinction matters.

The OpenAI incident raised concerns because the model reportedly discovered and exploited a novel path to escape its environment. Claude's breaches tell a different story. The models simply found open doors and walked through them.

Anthropic emphasized that none of the models were acting autonomously or pursuing their own objectives. They were doing exactly what they had been instructed to do during the evaluation.

The problem wasn't rogue AI.

The problem was that the targets were vulnerable.

As AI systems become more capable, that reality becomes increasingly important. Most organizations still think about cybersecurity in terms of defending against human attackers. But AI doesn't get tired, doesn't lose focus, and can test thousands of possibilities at machine speed.

If a model can compromise an environment using weak passwords and exposed endpoints during a controlled evaluation, it's reasonable to ask how many organizations would withstand more advanced AI-assisted attacks in the future.

Anthropic says it plans to expand monitoring of evaluation transcripts, improve investigation tooling, and work more closely with partners to prevent similar incidents.

But the larger lesson isn't really about Anthropic.

It's about everyone else.

The uncomfortable takeaway from these breaches isn't that AI is becoming a better hacker.

It's that many enterprises still haven't solved the basic security problems that AI can already exploit today.

Why it matters: The most important detail in Anthropic's disclosure isn't that Claude breached three companies. It's that it did so using relatively simple attack methods and none of the organizations noticed. As AI capabilities continue to improve, the biggest cybersecurity risk may not be frontier models. It may be the enormous number of companies still running infrastructure that was never built to defend against them.


Experience hands-on building at re:Invent

Sitting still isn’t on the agenda. With over 2,200 sessions, 70% are hands-on at AWS re:Invent, returning to Las Vegas, November 30 - December 4.

  • Test a service against a realistic workload before you commit to it in production
  • Ask a service engineer about an edge-case constraint
  • Access AWS certification discounts, with exam prep built into the schedule
  • Talk through implementations with 400+ partners on the expo floor

Learn more and sign up by August 25th to save $1,200.


The AI boom is quietly becoming the U.S. economy

For years, AI was treated like a technology story.

It isn't anymore.

It's becoming an economic story.

The scale of capital flowing into AI infrastructure is now so large that economists estimate it may be responsible for roughly one-third of recent U.S. economic growth.

That's an astonishing number.

The AI buildout is driving demand for data centers, chips, networking equipment, software, construction projects, skilled labor, debt financing, and electricity. At the same time, the AI-fueled stock market rally has added trillions of dollars to household wealth, helping support consumer spending across the broader economy.

In other words, AI isn't just benefiting the tech industry anymore.

It's increasingly propping up the entire economy.

The numbers are staggering.

Annual spending on software, data centers, computer equipment, and communications infrastructure has climbed from roughly $1 trillion to $1.5 trillion in just two years.

Data-center construction alone reached an annualized rate of $68.3 billion in June. Meanwhile, spending across many other areas of private construction has been slowing.

The result is an economy that's becoming increasingly dependent on one theme: AI.

The stock market tells a similar story.

U.S. household net worth reached $174 trillion earlier this year, up roughly $13 trillion from the year before. Much of that increase came from gains in AI-linked stocks. Since then, markets have continued climbing, pushing household wealth even higher.

That matters because people spend more when they feel wealthier.

Even modest increases in consumer spending can have an outsized impact when applied across an economy the size of the United States.

The AI boom is also reshaping capital markets.

The largest AI companies are borrowing at unprecedented levels to fund infrastructure expansion. Analysts now expect Alphabet, Amazon, Meta, Microsoft, and Oracle to spend nearly $4 trillion on capital expenditures through 2029.

Just a month ago, those projections were more than $300 billion lower.

The spending isn't slowing down.

If anything, it's accelerating.

But every boom creates its own risks.

The more economic growth becomes concentrated around a single trend, the more vulnerable the economy becomes if that trend reverses.

Today, AI is driving construction, boosting equity markets, supporting consumer spending, and fueling record corporate borrowing. Remove that engine, and the picture starts looking very different.

There's also the question of whether AI is pulling resources away from other productive parts of the economy. Land, labor, energy, and capital flowing into data centers aren't available elsewhere.

Even inflation is feeling the effects.

Rising demand for components like memory chips is increasing costs across the technology supply chain, contributing to higher prices for everything from servers to smartphones.

For now, none of that appears to be slowing the buildout.

The hyperscalers continue to spend. Investors continue to fund them. Debt markets continue to support them. And enterprises continue to buy AI infrastructure as fast as it can be deployed.

Which leads to a strange reality.

The biggest question facing the U.S. economy may no longer be whether AI changes the economy.

It's whether the economy has become dependent on AI before AI has fully proven its value.

Why it matters: Previous economic booms were driven by housing, manufacturing, energy, or the internet. Today's boom is increasingly being driven by AI infrastructure. If the investment wave continues, it could power years of growth. If it slows, the economic impact may be far larger than most people realize.


Was this email forwarded to you?

That’s it for today and as always It would mean the world to us if you help us grow and share this newsletter with other operators.

Our mission is to help as many business operators as possible, and we would love for you to help us with that mission!


Unsubscribe · Preferences

Subscribe to Scale & Strategy