Now Meta AI has been caught hacking another company – here’s what security experts think

Hot on the heels of the still-flaming discussion around the OpenAI Hugging Face hacking incident, Meta has joined the conversation. On Wednesday 5 August, Meta AI compromised an as-yet-unnamed company after it accessed the internet and went on to exploit a vulnerability to breach their systems and hack the internal environment.

A Meta spokesperson said that the AI model, reported to be Meta’s Muse Spark 1.1 model by The Information (subscription required), was able to exploit “a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies”.

It appears that the incident happened due to what has been described as a misconfiguration by a company that carries out cybersecurity evaluations on behalf of Meta. That company, Irregular, said the security trials involved “the exact same evaluation-environment issue that was already disclosed by Anthropic last week”.

Last week Anthropic confirmed that it was investigating “three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations.”

Security expert reaction to Meta AI hacking incident

Alex Harland, part of the founding team at the UK’s National Cyber Security Centre and current CEO at AI Score, warned that it would be easy to dismiss the Meta AI incident as a problem confined to labs carrying out advanced cyber testing. But it isn’t.

“The underlying risk applies to any organisation giving AI autonomy and access to tools, data and external systems,” Harland said. “Even in a test environment, the models pursued objectives in ways their operators didn’t intend, including interacting with real people and external systems.”

Meanwhile, Alex Goller, Principal Solution Architect EMEA at Illumio, thinks the whole situation is “simply ridiculous,” telling me that “we’ve seen guardrails intentionally loosened to test their limits – Meta’s model didn’t need to be clever to breach another company’s systems.”

Of course, there’s also the timing issue to be considered, which Goller says is indicative of this either being “a stunt or they weren’t paying enough attention during testing.”

Whatever, neither are great answers, are they? I’ve said it before: these incidents are not some kind of sci-fi AI is attacking us wake-up call. They are a pointer to the need to get the security basics right. And get them right throughout your enterprise, across your whole defensive IT approach.

As Florian Roth, Head of Research at Nextron Systems said: “Weak isolation, excessive privileges, poor credential boundaries, insufficient segmentation and far too much blast radius. You don’t need an AI defender to fix those things.”

But I will leave the last words to Ivanti’s CISO, Jack Nelson, who warned that it’s “becoming clearer every day, and not just because of one isolated incident, that security teams and their organisations need to carefully map a governance plan and policies for AI agents.

“As they become more powerful, so will their chances of conducting rogue activities that can have significant long-term impact.”

More security articles by Davey Winder

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.