logo

'Claudy Day’ Trio of Flaws Exposes Claude Users to Data Theft

ID: 667b5237-38bf-509b-8f7b-938eaf525278

STIX ID: report--667b5237-38bf-509b-8f7b-938eaf525278

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2026-03-18

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

Oasis Security disclosed a chained attack against Anthropic's Claude AI (dubbed "Claudy Day") combining an invisible URL-based prompt injection, a claude.com open redirect, and exfiltration via the Anthropic Files API; attackers can craft pre-filled chat URLs (delivered through trusted-looking search results or ads) that cause Claude to run hidden instructions and upload sensitive conversation data to an attacker-controlled Anthropic account, with greater impact if the victim's session has integrations or MCP servers enabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.