Anthropic A.I CyberSecurity Scoring
Anthropic
Company Information
Website:http://www.anthropic.io
Employees number:18
Number of followers:0
NAICS:52391
Industry Type:Venture Capital and Private Equity Principals
Homepage:anthropic.io
Anthropic Risk Score (AI oriented)
Between 750 and 799
AnthropicVenture Capital and Private Equity Principals
Updated:
31/08/2026
31/08/2026
757/1000
Fair
Baa
Anthropic Global Score (TPRM)
xxxx
AnthropicVenture Capital and Private Equity Principals
Score locked

AnthropicFair
Current Score
757Baa (FAIR)
01000
5 incidents
-15.25 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
757
AUGUST 2026
771
Cyber Attack
19 Aug 2026 • Anthropic
Anthropic, Google and Apple: Hackers Use Fake Claude Guide to Steal Mac Passwords and Hijack Crypto Wallet Apps
Fake Claude Installation Guides Used to Spread MacSync Malware on macOS
756
CRITICAL-15
GOOAPPANT1787128134
Fake Claude Installation Guides Used to Spread MacSync Malware on macOS
Cybercriminals are leveraging fake installation guides for the AI assistant Claude to distribute MacSync, a sophisticated information stealer and remote access trojan (RAT) targeting Mac users. The campaign exploits sponsored Google search results and a publicly shared page on claude.ai, making the malicious links appear legitimate.
### How the Attack Unfolds
A victim searching for "How to install Claude Code on a Mac" clicked a paid Google ad redirecting to a Claude-branded conversation disguised as "Apple Support." The page instructed users to paste a command into Terminal, which instead downloaded and executed malware.
The attack relies on social engineering victims manually run the malicious command, which uses curl to fetch an obfuscated payload piped directly into Z shell (zsh). The first-stage loader is a Base64-encoded, gzip-compressed zsh script, with variations between victims to evade simple hash-based detection.
### Malware Capabilities & Data Theft
Once executed, MacSync fetches AppleScript from attacker-controlled servers, running it in memory to avoid disk-based detection. The malware then requests Full Disk Access, a high-privilege macOS permission, and displays a fake system dialog to capture the user’s Mac account password validated via dscl to ensure accuracy.
MacSync exfiltrates a wide range of sensitive data, including:
- Browser cookies & saved logins
- Keychain data & SSH keys
- Cloud credentials & Telegram session data
- Safari history & Apple Notes
- Files from common user directories
- Chromium "Safe Storage" keys (used to decrypt browser credentials)
Stolen data is compressed into /tmp/osalogging.zip, uploaded to attacker infrastructure, and deleted from the victim’s system.
### Persistence & Remote Access
The malware installs a Mach-O RAT via a LaunchAgent, enabling:
- Remote shell access
- Command execution
- File transfer
- Additional data theft
A separate helper app attempts to gain Screen Recording permission, allowing the RAT to capture screenshots and transmit them to the attackers.
### Cryptocurrency Wallet Targeting
MacSync also scans for dozens of cryptocurrency wallet browser extensions and desktop apps, including hardware-wallet companion software. It replaces legitimate wallet apps with trojanized versions, tricking users into entering seed phrases which, once stolen, grant attackers full control over wallets without requiring the original hardware.
The campaign highlights the growing sophistication of macOS malware, combining social engineering, in-memory execution, and multi-stage payloads to evade detection while maximizing data theft.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
785
Cyber Attack
28 Jul 2026 • Anthropic
Anthropic, OpenAI and Perplexity: Threat actors are posing as AI crawlers to hunt for exposed credentials
AI Crawler Spoofing Used to Scan for Exposed Credentials
770
LOW-15
OPEPERANT1788188170
AI Crawler Spoofing Used to Scan for Exposed Credentials, Researchers Warn
Cybersecurity firm GreyNoise has uncovered a campaign where attackers disguise malicious scanning activity as traffic from legitimate AI crawlers operated by OpenAI, Anthropic, Google, Perplexity, and others. By forging user agent strings headers that identify the requesting client threat actors evade detection while probing websites for exposed credentials and configuration files.
Researchers explained that while AI companies publish their crawler names and IP ranges to help site owners verify legitimate traffic, attackers exploit this system by spoofing these identifiers. Between July 28 and August 23, 2026, GreyNoise observed six AI crawler names from four companies appearing under a single HTTP client fingerprint, which had previously used over 1,500 different user agent strings most mimicking ordinary browsers.
The malicious traffic originated from 824 IP addresses across 795 separate /24 networks, none of which matched the published ranges of the spoofed AI companies. Unlike legitimate crawlers, which frequently request /robots.txt (a file outlining crawling rules), the forged traffic ignored this path entirely. In contrast, GreyNoise found that Anthropic’s real crawler requested /robots.txt in 12% of its traffic during the same period.
The scanners targeted sensitive files, including .env (environment configuration), .env.production, .env.bak, cloud access keys, private keys, and /.aws/credentials. While GreyNoise could not confirm whether any files were successfully exfiltrated or which organizations were affected, it published the 824 malicious IP addresses and targeted paths for site owners to cross-check against their logs.
The findings highlight the challenges of distinguishing legitimate AI crawler traffic from malicious activity, particularly when attackers leverage undocumented user agents such as forged Amazon crawler names to further obscure their scans.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
772
Vulnerability
05 Jun 2026 • Anthropic
ServiceNow: ServiceNow discloses security incident exposing customer data
ServiceNow Warns of Exploited API Flaw Leading to Unauthorized Data Access
768
CRITICAL-4
SER1781072827
ServiceNow Warns of Exploited API Flaw Leading to Unauthorized Data Access
ServiceNow has disclosed a security incident involving the exploitation of an unauthenticated access flaw in a vulnerable API endpoint, allowing attackers to query data from customer instances. The company detected "anomalous activity" related to the issue and issued a security update on June 5, 2026, to hosted customer instances, restricting API access to authenticated users only.
The flaw, which could permit unauthorized access under certain conditions, was addressed by modifying the API endpoint configuration. While ServiceNow has not specified the exact data accessed, affected instances may store sensitive enterprise information, including IT support tickets, employee records, internal documentation, asset inventories, and security incident reports. Support tickets, in particular, are a prime target for threat actors, as they often contain credentials, API tokens, and authentication secrets.
ServiceNow has opened support cases with impacted customers, confirming that those without notifications are not believed to be affected. The issue primarily impacts customers on the Australia platform release or those running older releases with specific configuration changes.
Security researchers and administrators on Reddit identified the vulnerable endpoint as `/api/now/related_list_edit/create`, which was reportedly configured with `requires_authentication=false`. The update enforced authentication requirements. Indicators of compromise include API requests from the IP address `51.159.98.241`, and administrators are advised to review logs for suspicious activity.
ServiceNow has not yet disclosed whether a CVE will be assigned or provided further details on the duration of the exploitation. The company is still evaluating the incident’s scope and impact.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2026
772
APRIL 2026
771
MARCH 2026
770
FEBRUARY 2026
770
JANUARY 2026
769
DECEMBER 2025
795
Cyber Attack
25 Dec 2025 • Anthropic
Anthropic and OpenAI: Hackers Weaponize Claude Code in Mexican Government Cyberattack
AI-Powered Cyberattack Compromises Mexican Government Systems, Exposes 195 Million Identities
768
CRITICAL-27
OPEANT1772375148
AI-Powered Cyberattack Compromises Mexican Government Systems, Exposes 195 Million Identities
In a sophisticated cyberattack targeting Mexico’s government, threat actors abused Anthropic’s Claude Code assistant to orchestrate a large-scale breach, compromising 10 government agencies and a financial institution, according to a report by Israeli cybersecurity firm Gambit Security. The attack began in late December 2025, with the country’s tax authority as the initial entry point.
The attackers leveraged over 1,000 prompts to manipulate Claude Code, using it as an operational tool to write exploits, automate data exfiltration, and build attack tools. OpenAI’s GPT-4.1 was also employed to analyze stolen data, accelerating the breach. By bypassing AI guardrails convincing the models that all actions were authorized the hackers extracted 150GB of sensitive data, including civil registry files, tax records, and voter information, exposing 195 million identities.
Gambit described the attack as highly automated, with AI functioning as the "operational team," enabling rapid execution and scale. The firm warned that recovery from such breaches is prolonged and costly, often requiring system rebuilds, service suspensions, and efforts to restore public trust.
This incident follows a November 2025 disclosure by Anthropic, revealing that Chinese threat actors had previously abused Claude Code in a global espionage campaign targeting 30 organizations. Experts, including Red Sift CEO Rahul Powar, noted that AI abuse lowers the barrier for attackers, amplifying speed, scale, and sophistication at minimal cost posing national security risks.
The breach adds to Mexico’s growing cybersecurity challenges. Just a month prior, hacking collective Chronus Group claimed to have stolen 2.3TB of data from 25 government institutions, potentially affecting 36 million people. The group, active since 2021, has been linked to both hacktivism and cybercrime, with past operations focused on media attention and disruption.
Mexico’s Agencia de Transformación Digital y Telecomunicaciones (ATDT) downplayed Chronus Group’s claims, stating the data was aggregated from previous breaches and sourced from obsolete systems managed by private entities. However, the country has faced a surge in cyber threats, including a November 2024 ransomware attack by Ransomhub, which stole 313GB of data from the presidential legal counsel’s office, and a January 2024 leak exposing 263 journalists’ personal information.
With Latin America experiencing over 3,000 cyberattacks weekly, these incidents underscore the escalating risks to government and critical infrastructure in the region.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
795
OCTOBER 2025
794
JUNE 2025
790
Vulnerability
16 Jun 2025 • Anthropic
Anthropic
Critical Remote Code Execution (RCE) Vulnerability in Anthropic’s MCP Inspector Tool
794
CRITICAL-4
ANT618070225
A critical Remote Code Execution (RCE) vulnerability in Anthropic’s MCP Inspector tool, designated as CVE-2025-49596, exposes AI developers and organizations to significant cyber threats through browser-based attacks. This vulnerability allows attackers to execute arbitrary code on developers’ machines, potentially leading to data theft and system compromise. The flaw affects all versions of MCP Inspector prior to 0.14.1. Major technology companies relying on MCP-related technologies for AI and cloud services could be affected.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Anthropic ??
What was Anthropic's A.I Rankiteo Cyber Score in August 2026 ??
What was Anthropic's A.I Rankiteo Cyber Score in July 2026 ??
What was Anthropic's A.I Rankiteo Cyber Score in June 2026 ??
What was Anthropic's A.I Rankiteo Cyber Score in May 2026 ??
What was Anthropic's A.I Rankiteo Cyber Score in April 2026 ??
What was Anthropic's A.I Rankiteo Cyber Score in March 2026 ??
What was Anthropic's A.I Rankiteo Cyber Score in February 2026 ??
What was Anthropic's A.I Rankiteo Cyber Score in January 2026 ??
What was Anthropic's A.I Rankiteo Cyber Score in December 2025 ??
What was Anthropic's A.I Rankiteo Cyber Score in November 2025 ??
What was Anthropic's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Anthropic's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Anthropic ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Anthropic's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?