Hackers Used Claude to Breach OpenAI's Internal Systems and Access Employee Accounts

Claude, made by Anthropic, was used to compromise OpenAI's internal network and employee accounts. The breach succeeded because OpenAI's own security tools did not catch it. Someone submitted proof of access as a pull request to an OpenAI repository and it was accepted without intervention.
This fits the pattern where companies deploy security by tool loyalty rather than by actual threat model. OpenAI trusted its own systems and did not adequately monitor external tools operating within its perimeter. The pull request acceptance suggests either no review process or a review process that did not recognize the submission as hostile.
The next breach will probably also come through a pull request. Or it already has. The file that opened another file is still open.