A packaging and deployment misconfiguration at Anthropic resulted in approximately 500,000 lines of source code across around 2,000 files being uploaded to a public registry. Reporting characterises it as human error rather than a breach.
We file it deliberately, and the reasoning generalises well beyond this company.
Outcome, Not Narrative
Our database records what happened to data. A file becoming publicly available is the same outcome whether the cause was an intruder, a misconfigured database — as at IDMerit in 26-0219 — or a build script publishing more than intended.
Excluding self-inflicted exposure would make the database a record of adversary activity rather than of data exposure, and would systematically understate how organisations actually lose control of information.
Publishing Is A One-Way Door
Package registries are designed to be mirrored and cached. That is a feature: it makes builds reproducible and resilient. It also means an accidental publication is copied within minutes by systems nobody controls.
Deletion from the origin is therefore not remediation, and any organisation whose CI pipeline can publish to a public registry has an action available to it that cannot be undone. Very few treat that path with the ceremony they would apply to, say, a production database change.
The Honest Reason These Are Underreported
An intrusion has an adversary to point at. An accidental publication has only a decision somebody made, which makes disclosure organisationally harder and public sympathy thinner.
Which is a reason to notice when one is disclosed rather than quietly corrected — the disclosure is the part that is unusual, not the mistake.
Compiled from public reporting, listed below. This is recorded as an exposure rather than an intrusion; no attacker is alleged. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense