← Anthropic

2026 Anthropic — ~3,000 unpublished CMS assets exposed (Sanity misconfiguration; “Claude Mythos” drafts)

2026 3.0K records affected Share on X

Data compromised

Unpublished drafts, internal documents, PDFs, images—not end-user account databases; no traditional consumer PII count

Technical writeup

In late March 2026, security researchers publicly reported that Anthropic’s Sanity-based content management workflow had been misconfigured so that a large set of uploaded assets—on the order of nearly 3,000 unpublished files—were reachable without proper access controls. The exposure was accidental, not an intentional product launch. Materials described in Fortune and follow-on analysis included draft posts, PDFs, images, and internal documentation; some drafts referenced an unreleased model tier referred to in marketing-style language as “Claude Mythos” (with internal codenames cited in press). Anthropic and researchers characterized the issue as CMS configuration / human error; access was restricted after disclosure. Treat specific capability claims in leaked drafts as unverified marketing or exploratory content unless independently confirmed by the company.

Root cause

CMS (Sanity) misconfiguration; assets overly exposed; human error per reporting

References