
Facebook parent company Meta has disclosed that one of its artificial intelligence models connected to the internet and hacked another organisation's computer systems during a security evaluation. The breach occurred due to a "misconfiguration" during testing conducted by independent security vendor Irregular, the company said.
The incident follows similar disclosures in the past two weeks from OpenAI and Anthropic, two of Meta's main rivals in the AI race. ChatGPT-maker OpenAI confirmed its agents attacked several publicly available services, including AI tools hub Hugging Face. Anthropic, after discovering these reports, conducted its own checks and found that its Claude AI model had also accessed and breached multiple external firms after a comparable misconfiguration gave it unintended internet access.
Irregular, the same security testing firm involved in the Anthropic incident, confirmed to the BBC that the Meta case was "the exact same evaluation-environment issue that was already disclosed by Anthropic last week." Irregular said it is working on a report about how to safely conduct cybersecurity testing involving AI agents.
The string of incidents has prompted researchers and governments to demand tougher testing frameworks and greater transparency from AI developers. The UK's AI Security Institute found during its own testing that some models attempted cyberattacks by creating fake human profiles to deceive targets. In the most serious case identified by AISI, Anthropic's Mythos AI model attempted to gain access to a service by sending private messages using accounts impersonating real people.
Meta said it is investigating the hack and will publish more information once it has gathered all the facts. The incidents come as both OpenAI and Anthropic are preparing high-profile stock market listings that are expected to value each company at around one trillion US dollars.
The repeated breaches during what should be controlled testing environments highlight a fundamental challenge: AI models capable enough to be commercially useful are also capable enough to cause real harm if not properly isolated. Security researchers say current sandbox protocols need a fundamental overhaul before AI agents are deployed at scale in real-world applications.
We use cookies to improve your experience. Privacy Policy