Overview
Severity: HIGH | Affected: Anthropic | Category: breach
Anthropic announced a significant data breach impacting users of its Claude enterprise API. The incident, discovered on July 12, 2026, resulted from a misconfigured cloud storage bucket that inadvertently exposed API logs containing user prompts and model responses from a three-month period. The exposed data, affecting approximately 1.5 million enterprise accounts, did not include personally identifiable information like names or billing details, but the sensitive nature of the prompt histories poses a severe risk of intellectual property and confidential business data leakage. The company stated the misconfiguration was a result of human error during a routine infrastructure update. Anthropic has since secured the affected bucket, rotated all potentially compromised credentials, and is directly notifying all affected customers. They are also offering affected businesses a year of enhanced security monitoring services. The incident highlights the critical importance of robust cloud security posture management in the AI-as-a-Service ecosystem.