Mid-Migration, You're Defending Two Identity Platforms at Once

An AI evaluation just breached three real companies using basic techniques. Here's why that should worry anyone running a phased CIAM migration.

On July 30, Anthropic published a postmortem on its cybersecurity evaluations. Reviewing 141,006 test runs, it found three cases where models that were supposed to be sandboxed reached the open internet and compromised production systems at three different organizations. The models had been told they had no internet access. A misconfiguration meant they did — so when a task led them to real systems, they treated those systems as part of the exercise.

None of the break-ins were sophisticated. The models used weak passwords, unauthenticated endpoints, credentials left on a debug page, SQL injection, and an unclaimed software-package name. In one case a published package was running on 15 real systems within an hour. Two of the affected organizations only learned they'd been touched when Anthropic called them.

The identity protocols were never the problem. OAuth, OIDC, SAML, and platform authentication all held. What got exploited was the gap between the estate people thought they were running and the one that was actually live: something reachable that shouldn't have been, a credential where nobody expected it, a package name that quietly resolved to a public registry.

That gap is exactly what a phased migration creates.

The migration window is one long gap

During a phased migration, the legacy and target platforms run at the same time. The legacy tenant stays up for coexistence and rollback. The target platform gets everyone's attention because it's the future state. In between sit the things nobody is watching closely: old admin accounts, service credentials, callback URLs, and registration and consent endpoints built for a market you may have already exited. Gateway policies describe the target architecture accurately while an older route stays open just outside the migration team's scope.

Non-production environments add to it. They hold production-derived identity data, migration extracts, and representative datasets for testing volume and matching logic. When masking, access controls, and retention lag behind production, those environments become part of the exposure too.

The platform doesn't have to fail for any of this to bite. It only takes an operating estate that still holds something the plan no longer shows.

Your internal auth library is a supply chain

Anthropic's package incident has a direct parallel in CIAM. Most enterprises wrap their identity platform in an internal SDK so that dozens of downstream apps don't each reimplement token validation and session handling. That's the right call — but it concentrates trust in a single dependency.

If that package is named in onboarding docs or build scripts while its namespace sits unclaimed, and package managers can resolve the name from a public source, it becomes a supply-chain path into every system that installs it. For an auth SDK, those systems sit right next to credentials, tokens, and customer data. Namespace protection and version pinning belong in the identity estate, even though neither is a protocol concern.

What actually changed

Forgotten endpoints and stale credentials have always been risks. What used to protect them was cost: finding them took time, intent, and a reason to look at your company specifically. One model in Anthropic's review scanned roughly 9,000 hosts as a byproduct of finishing its assigned task. It never selected those targets — they just happened to sit on the path it was exploring.

That's the shift. The estate that used to hide behind obscurity can now be found by something that was never aiming at you. A legacy tenant doesn't stop being attack surface because your target architecture leaves it out.

Where this lands for a migration program

This is a governance problem, and it responds to governance. Keep the architecture, the migration plan, and the live estate reconciled — and treat decommissioning as a real step with a date, an owner, and evidence that the last dependency is gone. The window between the final production dependency and full decommissioning is where exposure concentrates, and it's the line most likely to get compressed when delivery dates slip.

That reconciliation is what our Advisory Services engagements are built for. Next Reason is a vendor-neutral CIAM specialist operating at enterprise scale: Akamai's Customer Migration Center of Excellence for AIC end-of-life, SOC 2 Type 2, with more than 65M customer identities migrated. We review identity architectures and migration plans independently, then stay alongside the teams that execute them.

If the decommissioning line in your plan has no date and no owner, that's a conversation worth having.

Source: Anthropic, Investigating three real-world incidents in our cybersecurity evaluations, July 30, 2026.

Nate Szytel, CEO, Next Reason