Anthropic accidentally exposes confidential data: what we know about the Claude Mythos leak

Introduction

In the world of technology, leaks of confidential information are not always the result of sophisticated cyberattacks: sometimes small human errors are enough to make public data that should have remained private. This is exactly what happened at the end of March 2026 to Anthropic, one of the leading artificial intelligence companies, known for developing the Claude assistant. The incident drew the attention of cybersecurity experts and the general public, becoming a case study in how technical carelessness can have significant consequences.

What happened

Around March 26 and 27, 2026, Fortune magazine discovered and reported the existence of an Anthropic data cache publicly accessible on the internet without any protection. Inside were approximately 3,000 unpublished pieces of content, including drafts of corporate blog posts. Among these materials, the existence of a new artificial intelligence model emerged, referred to by the code names “Claude Mythos” or “Capybara”, described as the most powerful model ever developed by the company, with significant advances in reasoning, programming, and cybersecurity capabilities. After being notified by Fortune, Anthropic resolved the issue and confirmed that it is indeed in the process of developing and testing this model. No hackers or malicious actors were involved: it was a configuration error, presumably human.

Why it matters and what impact it may have

Even without an actual attack, an incident of this type has concrete consequences. Anthropic operates in a highly competitive sector, where information about models under development represents a considerable strategic advantage. The early disclosure of details about a product not yet announced can influence the decisions of competitors, investors, and business partners. Furthermore, prematurely revealing the capabilities of an artificial intelligence system, including those related to cybersecurity, can raise questions about potential risks not yet publicly assessed. It is not currently known whether the data leak caused any measurable economic or reputational damage.

What companies and users can do

For companies, this episode is a reminder of how essential it is to regularly verify that their data storage systems are correctly configured and not accessible to anyone. Even data considered “non-critical”, such as drafts or internal documents, can contain sensitive information. Regular users, in this case, were not directly involved and do not need to take any specific action. However, it is always useful to be aware that the companies we interact with can be subject to this type of error.

Final takeaways

– Not all security incidents are caused by hackers: human errors in system configuration are a frequent and often underestimated cause of data leaks.

– Anthropic confirmed the existence of the Claude Mythos model, currently in the testing phase, after the news emerged as a result of the incident.

– The speed with which the company resolved the issue after Fortune’s report is a positive example of incident notification management.

Sources:
https://fortune.com/2026/03/26/anthropic-says-testing-mythos-powerful-new-ai-model-after-data-leak-reveals-its-existence-step-change-in-capabilities/
https://the-decoder.com/anthropic-leak-reveals-new-model-claude-mythos-with-dramatically-higher-scores-on-tests-than-any-previous-model/
https://fortune.com/2026/03/27/anthropic-leaked-ai-mythos-cybersecurity-risk/

Source: DataBreaches