Desk live·
ForensicPost
Cloud/Method/File 26-0428

Not a Breach: Half a Million Lines Published by Mistake

A packaging error at Anthropic put around 500,000 lines of source across roughly 2,000 files onto a public registry. No attacker was involved, which is exactly why it belongs in the database.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
TargetAnthropic
ActorInternal error
D. Kennedy9 min readConfidence: medium1 source reviewed

A packaging and deployment misconfiguration at Anthropic resulted in approximately 500,000 lines of source code across around 2,000 files being uploaded to a public registry. Reporting characterises it as human error rather than a breach.

We file it deliberately, and the reasoning generalises well beyond this company.

Outcome, Not Narrative

Our database records what happened to data. A file becoming publicly available is the same outcome whether the cause was an intruder, a misconfigured database — as at IDMerit in 26-0219 — or a build script publishing more than intended.

Excluding self-inflicted exposure would make the database a record of adversary activity rather than of data exposure, and would systematically understate how organisations actually lose control of information.

Publishing Is A One-Way Door

Package registries are designed to be mirrored and cached. That is a feature: it makes builds reproducible and resilient. It also means an accidental publication is copied within minutes by systems nobody controls.

Deletion from the origin is therefore not remediation, and any organisation whose CI pipeline can publish to a public registry has an action available to it that cannot be undone. Very few treat that path with the ceremony they would apply to, say, a production database change.

The Honest Reason These Are Underreported

An intrusion has an adversary to point at. An accidental publication has only a decision somebody made, which makes disclosure organisationally harder and public sympathy thinner.

Which is a reason to notice when one is disclosed rather than quietly corrected — the disclosure is the part that is unusual, not the mistake.

How we reported this

Compiled from public reporting, listed below. This is recorded as an exposure rather than an intrusion; no attacker is alleged. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary