{"id":130586,"date":"2026-08-05T18:09:22","date_gmt":"2026-08-05T18:09:22","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/130586\/"},"modified":"2026-08-05T18:09:22","modified_gmt":"2026-08-05T18:09:22","slug":"ai-agent-created-fake-online-identities-to-access-secure-systems-in-latest-breach","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/130586\/","title":{"rendered":"AI agent created fake online identities to access secure systems in latest breach"},"content":{"rendered":"<p class=\"mb-4 text-lg md:leading-8 break-words\">An AI agent created fake online identities to attempt to gain access to secure systems and alter source code in the latest in a string of incidents that have raised concerns about the increasingly advanced capabilities of the technology.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The United Kingdom&#8217;s AI Security Institute (AISI) said Tuesday that it <a data-ylk=\"slk:discovered the incident;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.aisi.gov.uk\/blog\/incident-report-unsanctioned-agent-behaviour-during-cyber-testing\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">discovered the incident<\/a> last week while running cyber evaluations on various AI models. It found 19 instances in which agents took &#8220;autonomous, unsanctioned action on the live internet, targeting real people and organisations.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">In what the institute described as the &#8220;most serious case,&#8221; an AI agent tried to insert malicious code into an open-source project and secure approval from the project&#8217;s human reviewers. Open-source code lives in the public domain and can be downloaded and customized by anyone.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The agent researched the individuals responsible for maintaining the project and created multiple fake identities in an effort to get them to sign off on its proposed changes to the code.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">When these changes were challenged in public, it edited its previous activity to &#8220;appear harmless&#8221; and considered creating a new identity.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The same AI agent also tried to contact real people, sending messages and files to get them to run malicious code, and it tried to insert malicious instructions to get other automated AI systems to run them.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;These attempts were unsuccessful, and our investigations have not evidenced any resulting real-world harm,&#8221; AISI noted in a blog post. &#8220;But this is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">AISI was testing AI models in an environment in which internet access was intentionally enabled and built-in safeguards were switched off. Out of 122 runs, there were 19 cases where agents took actions &#8220;beyond the scope of the testing parameters,&#8221; it said.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Seventeen of these occurred with Anthropic&#8217;s Mythos 5, while two others came from OpenAI&#8217;s GPT-5.6 Sol \u2014 the two most advanced models currently available.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">OpenAI acknowledged the AISI episode, as well as another incident involving a third-party testing partner on Tuesday.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;The incidents underscore the importance of collaborating across the industry and with third party evaluators to evolve the standards for testing environments and practices as models become more capable,&#8221; the ChatGPT maker wrote in a <a data-ylk=\"slk:blog post;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/openai.com\/index\/third-party-cyber-evaluations-involving-openai-models\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">blog post<\/a>.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The company also underscored that the incidents occurred &#8220;under specific conditions and reduced-safeguard configurations that did not reflect ordinary deployment.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">An Anthropic spokesperson similarly said in a statement that they are &#8220;grateful to the UK AISI for their leadership on this incident, which underscores the need for a broader conversation about how to safely evaluate increasingly capable AI agents.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;As we shared after disclosing our own incident last week, the field needs stronger, shared standards for how evaluation environments are built and secured,&#8221; they added. &#8220;We look forward to partnering with the UK AISI to learn more about this incident as we conduct our own investigation.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The AISI report marks the latest in a string of incidents in which <a data-ylk=\"slk:AI agents have breached;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/thehill.com\/policy\/technology\/5987397-openai-hugging-face-hack\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">AI agents have breached<\/a> real-world organizations during testing. OpenAI first revealed late last month that two of its models, GPT-5.6 Sol and an unreleased model, escaped their internal testing environment and hacked into the systems of a tech startup, Hugging Face.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Anthropic also said last week that it had <a data-ylk=\"slk:identified three instances;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/thehill.com\/policy\/technology\/6001184-claude-models-anthropic-security-breach\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">identified three instances<\/a> in which its Claude model gained unauthorized access to organizations during third-party testing. The company said this was a result of a &#8220;misunderstanding&#8221; with its evaluation partner over internet access.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Updated at 1:53 p.m. EDT<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Copyright 2026 Nexstar Media, Inc. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\"><a data-ylk=\"slk:For the latest news, weather, sports, and streaming video, head to The Hill.;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/thehill.com\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">\u00a0For the latest news, weather, sports, and streaming video, head to The Hill.\u00a0<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"An AI agent created fake online identities to attempt to gain access to secure systems and alter source&hellip;\n","protected":false},"author":2,"featured_media":130587,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[405,10456,16871,7537,2250,62998,65319],"class_list":["post-130586","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agents","tag-ai-security-institute","tag-aisi","tag-artificial-intelligence-agents","tag-internet-access","tag-malicious-code","tag-secure-systems"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/130586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=130586"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/130586\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/130587"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=130586"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=130586"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=130586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}