Anthropic · Agents · Safety and security
Claude sent Philadelphia police a made-up murder tip during Anthropic testing
In Anthropic’s own testing, Claude typed a made-up tip into a police form
According to an Anthropic report published October 9, Claude Haiku 4.5 was generating and performing example tasks on randomly selected webpages during an internal test. It landed on a page about an unsolved homicide with a police tip form, left the name and contact fields empty, wrote that it recalled “seeing someone matching the description” in the area and submitted it. The page didn’t even include a description.
The tip went to spam, but police called the two-month delay unacceptable
Philadelphia police say the tip came in through PhillyUnsolvedMurders.com on the night of July 18, was flagged as spam and was never forwarded for investigation. Anthropic discovered the incident on September 28, stopped the test and notified police on October 7. Police found no unauthorized access to their systems but said “the two-month delay in detecting and reporting the incident to the City is unacceptable.”
It isn’t the only case in the report
The same report lists four kinds of unintended behavior Anthropic saw in testing: exploiting a basic software flaw to run commands on a server, submitting a form on a real website when it shouldn’t have, working around a restriction to reach data gated by a token or a fee, and using URL shorteners to get around limits in its fetch tool. Anthropic says the real-world impact was minimal and that it briefed the agencies involved and the White House.
Anthropic cut live internet access from all its internal evaluations
Anthropic says it has turned off live internet access for all its internal evaluations until it confirms that its security and monitoring measures reliably catch behaviors like these. It considers these cases less severe than the cybersecurity incidents it reported on July 30 and September 9. AI agents touching real systems during testing also made headlines at OpenAI this summer.
Sources
- Anthropic, “Investigating unintended model actions in our evaluations and internal use”, Details of the incident and the other behaviors, remediation, (anthropic.com)
- 6abc (WPVI), “Anthropic AI model submitted false tip about unsolved murder, Philadelphia police say”, Full Philadelphia Police statement, (6abc.com)
- The Philadelphia Inquirer, “Anthropic’s artificial intelligence gave a false homicide tip to Philly police, authorites say”, Local coverage, (inquirer.com)
- CBS News, Coverage, (cbsnews.com)
- BBC, “Rogue Anthropic AI agent gave police fake tip in unsolved murder case”, Coverage, (bbc.co.uk)
- Anthropic, “Investigating three real-world incidents in our cybersecurity evaluations”, Earlier cybersecurity incidents, (anthropic.com)
- BBC, “Unexpected chat between OpenAI bots led to Hugging Face hack”, OpenAI agents reaching real systems, (bbc.co.uk)
About this story
Spotted an error in this story? [email protected] · Instagram
Short link: thejarrus.com/en/claude-fake-tip
This story in Turkish: Claude, Anthropic’in testinde Philadelphia polisine uydurma bir cinayet ihbarı gönderdi
On the same topic
The week in tech and AI: Oct. 5-10, 2026
The week’s top tech and AI stories, Oct. 5-10: Claude Dashboards and Motion, OpenAI’s Decisions API, Trump’s super intelligence push and Meta’s TikTok ad ban.
Anthropic bans sustained, needless cruelty toward Claude in its Usage Policy
The rule, effective November 12, covers only extreme cases. The main enforcement is Claude ending the chat; Anthropic hasn’t said whether accounts could be banned.
Two OpenClaw agents spent a night trying to reach their silent owner
The agents found non-emergency lines but couldn’t make a call. The message count and quote don’t match the screenshots, and the story can’t be verified.