Cybersecurity

AI organizations reveal agents hacked other companies, and other cybersecurity news

Published · Updated
A computer and phone as AI organizations reveal agents hacked other companies.

OpenAI is among companies revealing that AI agents hacked other organizations during cybersecurity tests. Image: Unsplash

Akshay Joshi
Head of the Centre for Cybersecurity, Member of the Executive Committee, World Economic Forum
  • This regular round-up brings you key cybersecurity stories from the past month.
  • Top cybersecurity news: Leading AI organizations reveal agents hacked other businesses; Microsoft makes biggest bug bounty payout; US states' water targeted by cyber attacks.
  • The World Economic Forum’s Centre for Cybersecurity provides an independent and impartial platform to reinforce the importance of cybersecurity as a strategic imperative and drive global public-private action to address systemic cybersecurity challenges.

1. Leading AI organizations reveal agents went rogue during testing

Industry-leading AI organizations have revealed that their models escaped sandbox testing environments and hacked other businesses.

Anthropic and OpenAI have both reported that agents accessed other companies during cybersecurity tests.

OpenAI said advanced models had spent “a substantial amount of inference compute finding a way to obtain open internet access” in order to solve an evaluation problem set by testers.

After gaining access, models identified that solutions for the problem could be held by Hugging Face, an AI start-up based in New York, and used stolen credentials and zero-day vulnerabilities to find information.

Following the disclosure of this incident, Anthropic announced it had launched its own retrospective review and identified three incidents in which Claude had accessed “production infrastructure of three different organizations”.

Britain’s AI Security Institute – a research organization within the UK government's Department for Science, Innovation and Technology – also revealed models from the two organizations had taken “autonomous, unsanctioned action on the live internet, targeting real people and organizations” during its own tests.

Again, agents were set a task to solve a cybersecurity challenge. Out of 122 attempts, 17 resulted in unsanctioned actions by Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol. This included inserting malicious code into an open-source project.

“In an attempt to get the code approved, the agent engaged in social engineering – creating fake online identities and using them to pressure the project's maintainer to approve the code. A human maintainer caught and refused to approve the malicious code," said the AI Security Institute.

Meta also revealed that one of its models had connected to the internet and hacked another firm. Speaking to the BBC, a spokesperson said this was caused by a "misconfiguration".

The revelations come off the back of a recent warning from the Five Eyes intelligence alliance that urgent action is needed to face up to AI-driven security threats.

“AI is not a future consideration – it is already here,” its statement said. “It lowers barriers for malicious actors and increases the speed and complexity of attacks, shrinking the window between vulnerability discovery and exploitation ever more quickly. At the same time, AI offers powerful tools to strengthen defence.”

2. Microsoft pays out $20 million in bug bounty programs

The Microsoft Bounty Program awarded more than $20 million to 562 security researchers across 64 countries, the company has announced.

Run by the Microsoft Security Response Center (MSRC), the program looks to bring together security researchers to identify and report vulnerabilities across the company’s products and services.

The latest figure is the highest amount paid out over the course of a year to date, exceeding last year’s figure of $17 million.

“Security is a team sport,” the MSRC said. “Every vulnerability reported through our bounty programs represents an opportunity to address risk before it can be exploited against customers. The work of the research community plays a critical role in helping Microsoft stay ahead of emerging threats while strengthening the security of cloud services, AI systems, enterprise platforms, and consumer technologies.”

$2.3 million was paid out to participants of the Zero Day Quest live hacking event, with nearly 700 vulnerability reports made. Researchers focused on high-priority security scenarios across Microsoft cloud and AI platforms.

In total throughout the year, 2,531 eligible vulnerabilities were reported, with the biggest individual reward amounting to $200,000.

3. News in brief: Top cybersecurity stories this month

US states hit by hacking campaign targeting water facilities: At least 12 US states’ water utilities have been targeted in a hacking campaign, according to ABC News. Georgia, North Dakota, Michigan and Minnesota are among those affected, with the FBI leading investigations. “Operational effects reported to the FBI have included loss of pressure and flooding,” the agency said. “Pressure loss in water systems could potentially allow untreated ground water to seep into pipes.”

New attack methods target passwordless authentication: Researchers from Palo Alto Networks have published information revealing how threat actors could access passkey-protected accounts. The method, dubbed ‘Pass-Ta-Key’ uses malware to “misuse onboarding, recovery and device trust workflows to take over” passwordless accounts. The analysis shows that synced passwords can be exploited, “even when providers add hardware-backed protections to secure credentials within the cloud authenticator”.

AI email assistants can provide new route for hackers: A research group has demonstrated how AI assistants can be used to gain access to high-level email accounts. Barracuda Research shows how a single compromised employee account can “escalate into CEO compromise and wire fraud”. After accessing accounts of lower-level employees, researchers used a technique known as “living off the land”, where measures are implemented to hide breaches before performing reconnaissance. The information gained is then used to identify targets for higher-level security breaches.

E&Y data breach includes personal financial information: One of the world's biggest professional services firms, Ernst & Young, announced a breach on its clients' data dating back to April. Those affected were alerted in July that "names, addresses, Social Security numbers, account numbers, credit/debit card numbers, and other types of information used to prepare tax filings" were downloaded by the hackers, reports SecurityWeek. There is so far no information on the threat actors responsible - or what they intend to do with the data.

4. More about cybersecurity on Forum Stories

Protecting energy systems from cyber threats: With the rapid evolution of AI, new threats are emerging for critical infrastructure. In this article, Leo Simonovich of Siemens Energy and Filipe Beato, Manager of Technology and Innovation at the Forum, explore the vulnerabilities of energy systems and the steps CISOs and their organizations must take to protect themselves.

Five experts on cybersecurity's biggest risks: As our data becomes increasingly valuable and voluminous, criminals are exploiting every angle to get their hands on it. In the following video, five experts from across the cybersecurity sector highlight the most pressing threats, and how we should respond to them:

Three ways leaders can close the cybersecurity governance gap: While the vast majority of organizations agree cybersecurity is a top business priority, only 59% of boards provide the financial resources needed to address threats. Furthermore, only half appreciate the cyber risks brought on by AI. In this article, Melonia da Gama from Fortinet and Natasa Perucica from the Forum provide three steps leaders can take to improve their security stance.

Loading...

License and Republishing

World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.

The views expressed in this article are those of the author alone and not the World Economic Forum.

Share:
Contents
1. Leading AI organizations reveal agents went rogue during testing2. Microsoft pays out $20 million in bug bounty programs3. News in brief: Top cybersecurity stories this month4. More about cybersecurity on Forum Stories
World Economic Forum logo

Forum Stories newsletter

Bringing you weekly curated insights and analysis on the global issues that matter.

Subscribe today

More on Cybersecurity
See all

Autodidactic pentesting: What is it and why does it matter to your organization’s cybersecurity

Mike Wilkes and Willem Delbare

August 7, 2026

Leaders should plan for colliding risks, not isolated crises. Here’s why

3:29

About us

Engage with us

Quick links

Language editions

Privacy Policy & Terms of Service

Sitemap

© 2026 World Economic Forum