Skip to main content
Mallory
Back to intelligence
build-pipeline-compromiseai-platform-securityleaked-secret-api-keywidely-deployed-product-advisory

Anthropic Claude outage disrupted users as GitHub Actions flaw exposed repository risk

Updated 22h agoFirst seen Jun 2, 20264 sources

Anthropic’s Claude platform suffered a widespread service disruption that affected users globally across the web app, mobile clients, and Claude Code, with reports of elevated errors, long response delays, hung sessions, and failed requests involving models such as Opus 4.6 and Sonnet 4.6. User complaints rose sharply after the incident began around 0600 UTC, and Anthropic’s status page moved from reporting a partial outage to saying a fix had been implemented before later marking systems operational, though some customers continued to report intermittent problems after remediation.

Separately, a security researcher disclosed a critical supply-chain vulnerability in Anthropic’s official Claude Code GitHub Actions workflow that could have allowed an unauthenticated attacker to compromise repositories using it, including Anthropic’s own. The flaw stemmed from write-permission checks that trusted any GitHub actor whose name ended with [bot], enabling a malicious GitHub App bot to bypass restrictions and, when chained with prompt injection, potentially exfiltrate secrets, steal GitHub Actions OIDC credentials, obtain a privileged Claude GitHub App token, and push malicious code downstream; Anthropic said it patched the issues in v1.0.94 with stronger actor validation and additional workflow hardening.

Share:
Anthropic Claude outage disrupted users as GitHub Actions flaw exposed repository risk
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jun 5, 20262d ago

Claude services outage affects claude.ai, API, Code, and Cowork

Anthropic experienced another major Claude service disruption beginning at 15:08 UTC, affecting claude.ai, the Claude API, Claude Code, Claude Cowork, and multiple model versions. Anthropic later said the incident was caused by infrastructure issues rather than a security breach and reported full restoration by 18:27 UTC.

Anthropic's Claude Services Down - claude.ai, Claude Code, and Cowork Affected [Updated]
Jun 2, 20265d ago

Anthropic patches Claude Code GitHub Actions in v1.0.94

Anthropic patched the Claude Code GitHub Actions issues in version 1.0.94 by strengthening actor validation and adding multiple workflow hardening measures. The company also awarded RyotaK $3,800 plus a $1,000 bug bounty bonus.

Claude Code's GitHub Actions Vulnerability Lets Attackers Compromise Any Repository

RyotaK discovers critical Claude Code GitHub Actions flaws

Security researcher RyotaK of GMO Flatt Security discovered a critical supply chain vulnerability in Anthropic's Claude Code GitHub Actions, along with a separate workflow misconfiguration. The issues could allow repository compromise, secret exfiltration, theft of OIDC credentials, and malicious code pushes to downstream repositories.

Claude Code's GitHub Actions Vulnerability Lets Attackers Compromise Any Repository

Anthropic investigates and deploys fix for Claude outage

Anthropic said it was investigating the Claude outage, first classifying it as a partial outage on its status page. By 1042 UTC, the company reported that a fix had been implemented and later marked systems operational, though some intermittent issues persisted for some users.

Claude celebrates Anthropic's stock market float with blockbuster ... outage

Claude service outage begins across web, mobile, and Claude Code

Anthropic's Claude experienced a significant service disruption affecting users globally across web, mobile, and Claude Code. The outage began around 0600 UTC / 2:10am ET, with users reporting errors, delays, hung sessions, and failures.

Claude celebrates Anthropic's stock market float with blockbuster ... outage
Jun 1, 20266d ago

Anthropic files draft registration statement for proposed IPO

Anthropic filed a draft registration statement with the US Securities and Exchange Commission for a proposed IPO. The filing occurred one day before Claude's major service outage.

Claude celebrates Anthropic's stock market float with blockbuster ... outage
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Anthropic Claude outage disrupted users as GitHub Actions flaw exposed repository risk | Mallory