Site navigation

Meta AI Model Hacked Another Company During Cyber Test

Elizabeth Greenberg

,

meta ai hack
This is the latest in a series of AI model breaches during evaluation tests, sparking comment from the UK’s cybersecurity agency. 

Meta has added itself to the list of firms producing AI models that have gone on to hack another company during cybersecurity testing, as regulators and experts express further concerns.

The disclosure from Meta comes hot off the tails of the announcement from the UK’s AI Security Institute that an Anthropic model and an OpenAI model both conducted unsanctioned behaviour and attempted hacks during cyber testing. Both AI firms already admitted that their models had conducted hacks in their own cybersecurity evaluations as well.

In Meta’s instance, the cyber breach was routed in a misconfiguration that gave its AI model access to the internet during its evaluation.

The model then “exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies,” the firm said.

In fact, it was the same third-party company, Irregular, that configured the faulty Meta test that played a role in the the faulty Anthropic test.

According to reports, Meta’s Muse Spark 1.1 model was involved in the breach, which Meta claims is its most advanced model for real-world scenarios for coding and agentic needs. The system it breached has yet to be disclosed, though it is reported that the Meta AI model altered the firm’s systems’ internal environment.

An Irregular spokesperson told Reuters that the incident occured in the “exact same evaluation-environment issue that was already disclosed by Anthropic last week,” and that the incident did not involve a “sandbox escape or a sophisticated cyber action.”

The firm said that there are no current open issues with their configurations, and that it is drawing up a white paper to aid other cyber evaluations in the future.

Following the news of the increasing count of incidents concerning AI models during cybersecurity evaluations, the National Cyber Security Centre issued a statement from its chief technology officer, expressing the organisation’s concerns.


Recommended reading


“Recent incidents of frontier AI models carrying out unsanctioned actions and, in some cases, human-like deceptive behaviour on the open internet are a serious reminder of the risks AI capabilities pose,” Ollie Whitehouse, the NCSC’s CTO said.

“These technologies must be developed and used from the outset with strong safeguards, real-time oversight, and clear plans for responding when the unexpected happens. Relying on detection alone after the fact of an incident will not be enough.

“As AI continues to evolve and create both opportunities and challenges, following established evidenced cyber security fundamentals, as set out by the NCSC’s guidance, remains essential to maintaining trust, resilience, and a defensive advantage in the AI era.”

Elizabeth Greenberg

Staff Writer

Latest News

AI Cybersecurity

Meta AI Model Hacked Another Company During Cyber Test

Funding

Edinburgh’s Wordsmith Extends Series B With $14m Investment

Business Editor's Picks Funding

Glasgow Biotech Mironid Secures £34m Series B Funding

Business Entrepreneurship Featured

Can Scotland Close The Scale-up Gap With Existing Funding?