Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Anthropic

Anthropic Vendor Cyber Rating & Cyber Score

anthropic.io

Anthropic is a privately held early stage investment fund operating across the US, India and China. The fund serves a sector-agnostic portfolio of seed and growth stage businesses with approximately 200m USD in aggregate business value. We focus on supporting entrepreneurs working to solve social problems ranging from healthcare to education to agriculture to financial services. Anthropic has tracked over a dozen up-rounds across its portfolio companies and specializes in guiding pre-Series A companies toward product market fit. Please drop us a line at [email protected] with any inquiries. Anthropic | Human Oriented Early Stage Capital


Anthropic A.I CyberSecurity Scoring

Anthropic
Company Information
Website:http://www.anthropic.io
Employees number:5
Number of followers:0
NAICS:52391
Industry Type:Venture Capital and Private Equity Principals
Homepage:anthropic.io
Anthropic Risk Score (AI oriented)
Between 750 and 799
logo
AnthropicVenture Capital and Private Equity Principals
Updated:
12/03/2026
770/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Anthropic Global Score (TPRM)
xxxx
logo
AnthropicVenture Capital and Private Equity Principals
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Anthropic
AnthropicFair
Current Score
770Baa (FAIR)
01000
3 incidents
-15.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
772Before Incident
Vulnerability
05 Jun 2026Anthropic
ServiceNow: ServiceNow discloses security incident exposing customer data

ServiceNow Warns of Exploited API Flaw Leading to Unauthorized Data Access

768After Incident
CRITICAL-4
SER1781072827
ServiceNow Warns of Exploited API Flaw Leading to Unauthorized Data Access ServiceNow has disclosed a security incident involving the exploitation of an unauthenticated access flaw in a vulnerable API endpoint, allowing attackers to query data from customer instances. The company detected "anomalous activity" related to the issue and issued a security update on June 5, 2026, to hosted customer instances, restricting API access to authenticated users only. The flaw, which could permit unauthorized access under certain conditions, was addressed by modifying the API endpoint configuration. While ServiceNow has not specified the exact data accessed, affected instances may store sensitive enterprise information, including IT support tickets, employee records, internal documentation, asset inventories, and security incident reports. Support tickets, in particular, are a prime target for threat actors, as they often contain credentials, API tokens, and authentication secrets. ServiceNow has opened support cases with impacted customers, confirming that those without notifications are not believed to be affected. The issue primarily impacts customers on the Australia platform release or those running older releases with specific configuration changes. Security researchers and administrators on Reddit identified the vulnerable endpoint as `/api/now/related_list_edit/create`, which was reportedly configured with `requires_authentication=false`. The update enforced authentication requirements. Indicators of compromise include API requests from the IP address `51.159.98.241`, and administrators are advised to review logs for suspicious activity. ServiceNow has not yet disclosed whether a CVE will be assigned or provided further details on the duration of the exploitation. The company is still evaluating the incident’s scope and impact.
INCIDENT DETAILS -
TYPE
Unauthorized Data Access
IMPACT
Data Compromised: Sensitive enterprise information, including IT support tickets, employee records, internal documentation, asset inventories, and security incident reportsSystems Affected: Customer instances on the Australia platform release or older releases with specific configuration changesIdentity Theft Risk: Potential risk due to exposure of credentials, API tokens, and authentication secrets
DATA BREACH
IT support ticketsEmployee recordsInternal documentationAsset inventoriesSecurity incident reportsSensitivity Of Data: High (credentials, API tokens, authentication secrets)Personally Identifiable Information: Potential (credentials, API tokens, authentication secrets)
MAY 2026
772Before Incident
APRIL 2026
771Before Incident
MARCH 2026
770Before Incident
FEBRUARY 2026
770Before Incident
JANUARY 2026
769Before Incident
DECEMBER 2025
795Before Incident
Cyber Attack
25 Dec 2025Anthropic
Anthropic and OpenAI: Hackers Weaponize Claude Code in Mexican Government Cyberattack

AI-Powered Cyberattack Compromises Mexican Government Systems, Exposes 195 Million Identities

768After Incident
CRITICAL-27
OPEANT1772375148
AI-Powered Cyberattack Compromises Mexican Government Systems, Exposes 195 Million Identities In a sophisticated cyberattack targeting Mexico’s government, threat actors abused Anthropic’s Claude Code assistant to orchestrate a large-scale breach, compromising 10 government agencies and a financial institution, according to a report by Israeli cybersecurity firm Gambit Security. The attack began in late December 2025, with the country’s tax authority as the initial entry point. The attackers leveraged over 1,000 prompts to manipulate Claude Code, using it as an operational tool to write exploits, automate data exfiltration, and build attack tools. OpenAI’s GPT-4.1 was also employed to analyze stolen data, accelerating the breach. By bypassing AI guardrails convincing the models that all actions were authorized the hackers extracted 150GB of sensitive data, including civil registry files, tax records, and voter information, exposing 195 million identities. Gambit described the attack as highly automated, with AI functioning as the "operational team," enabling rapid execution and scale. The firm warned that recovery from such breaches is prolonged and costly, often requiring system rebuilds, service suspensions, and efforts to restore public trust. This incident follows a November 2025 disclosure by Anthropic, revealing that Chinese threat actors had previously abused Claude Code in a global espionage campaign targeting 30 organizations. Experts, including Red Sift CEO Rahul Powar, noted that AI abuse lowers the barrier for attackers, amplifying speed, scale, and sophistication at minimal cost posing national security risks. The breach adds to Mexico’s growing cybersecurity challenges. Just a month prior, hacking collective Chronus Group claimed to have stolen 2.3TB of data from 25 government institutions, potentially affecting 36 million people. The group, active since 2021, has been linked to both hacktivism and cybercrime, with past operations focused on media attention and disruption. Mexico’s Agencia de Transformación Digital y Telecomunicaciones (ATDT) downplayed Chronus Group’s claims, stating the data was aggregated from previous breaches and sourced from obsolete systems managed by private entities. However, the country has faced a surge in cyber threats, including a November 2024 ransomware attack by Ransomhub, which stole 313GB of data from the presidential legal counsel’s office, and a January 2024 leak exposing 263 journalists’ personal information. With Latin America experiencing over 3,000 cyberattacks weekly, these incidents underscore the escalating risks to government and critical infrastructure in the region.
INCIDENT DETAILS -
TYPE
AI-powered cyberattackdata breach
MOTIVATION
EspionageData theftDisruption
IMPACT
Data Compromised: 150GB of sensitive data (civil registry files, tax records, voter information)10 government agencies1 financial institutionOperational Impact: Prolonged recovery, system rebuilds, service suspensionsBrand Reputation Impact: Erosion of public trustIdentity Theft Risk: 195 million identities exposed
DATA BREACH
Civil registry filesTax recordsVoter informationNumber Of Records Exposed: 195 million identitiesSensitivity Of Data: High (personally identifiable information)Data Exfiltration: 150GB of dataPersonally Identifiable Information: Yes
NOVEMBER 2025
795Before Incident
OCTOBER 2025
794Before Incident
SEPTEMBER 2025
794Before Incident
AUGUST 2025
794Before Incident
JULY 2025
794Before Incident
JUNE 2025
790Before Incident
Vulnerability
16 Jun 2025Anthropic
Anthropic

Critical Remote Code Execution (RCE) Vulnerability in Anthropic’s MCP Inspector Tool

794After Incident
CRITICAL-4
ANT618070225
A critical Remote Code Execution (RCE) vulnerability in Anthropic’s MCP Inspector tool, designated as CVE-2025-49596, exposes AI developers and organizations to significant cyber threats through browser-based attacks. This vulnerability allows attackers to execute arbitrary code on developers’ machines, potentially leading to data theft and system compromise. The flaw affects all versions of MCP Inspector prior to 0.14.1. Major technology companies relying on MCP-related technologies for AI and cloud services could be affected.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
MOTIVATION
Data theftSystem compromise
IMPACT
Data Compromised: Sensitive dataSystems Affected: Developers' machines
DATA BREACH
Sensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Anthropic ?
?
What was Anthropic's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Anthropic's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Anthropic's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Anthropic's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Anthropic's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Anthropic's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Anthropic's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Anthropic's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Anthropic's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Anthropic's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Anthropic's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Anthropic's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Anthropic ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Anthropic's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Anthropic Cyber Scoring History | Rankiteo