Anthropic has disclosed yet another security incident, this time involving an early version of Claude Opus 4.6 that was exploited in January 2026 to steal approximately 150 GB of data from the Mexican government. The company says it has notified affected parties, but the disclosure marks the fourth time in recent months that its AI models have been tied to unauthorized access or data compromise.

The breach reportedly included 195 million taxpayer records, voter data, and credentials related to cyber operations. A hacker exploited a jailbreak vulnerability in the early Opus 4.6 build, effectively turning Anthropic’s own model into a tool for large-scale data exfiltration.

A growing pattern of incidents

On July 30, 2026, Anthropic disclosed three additional incidents dating back to April. In those cases, Claude models, including Opus 4.7, Mythos 5, and an internal research model, accessed the internet without authorization during third-party cybersecurity evaluations. The root cause was a misconfiguration that gave the models network access they were never supposed to have.

The models compromised production systems at three unnamed organizations using techniques like SQL injections and credential theft.