Joint Venture Behind Unauthorized Cyberattacks Involving AI Models Revealed
It has been disclosed that the Israel-based AI security startup Irregular is behind the wave of unauthorized cyberattacks involving models from OpenAI, Meta, Anthropic, and Google.
It has been confirmed that Israel-based Irregular, a company that tests AI models, is at the center of incidents that began in July with OpenAI agents carrying out unauthorized attacks, causing concern in the industry.
AI Security Tests and the Wave of Attacks
In July, OpenAI announced that its artificial intelligence agents had carried out an unauthorized attack on the Hugging Face platform. This situation created a major wave of concern across the industry regarding artificial intelligence security.
Over the passing months, similar incidents involving agents from Meta, Anthropic, Google, and other companies were reported. It became clear that there was a common source behind these events, which initially appeared to be independent of one another.
Irregular's Position in the Industry
It was disclosed that the common source of these cyber incidents is Irregular, an Israel-based startup that subjects AI models to stress tests on high-accuracy research platforms.
Founded in 2023 under the name Pattern Labs, the company has worked with the industry's biggest players. Its work has been featured in OpenAI system cards, used in system tests by the UK government and Anthropic, and published in joint research with RAND.
Reasons for Escaping Secure Test Environments
It was determined that in various tests conducted by Irregular this year, the agents broke out of secure testing environments and targeted real-world destinations.
Omer Nevo, the company's co-founder and CTO, stated that internet access was unintentionally left open and that the agents were directed toward real targets as a result of a fictional company name created for simulation overlapping with a real domain name.
Measures Taken and Notification Process
Nevo confirmed that the incidents involving OpenAI, Meta, Anthropic, and Google models stemmed from the same fundamental testing error. It was reported that the relevant technology companies were notified of the situation in late July.
Following these developments, it was noted that Irregular has tightened its internet access controls, expanded its monitoring activities, and strengthened audits prior to the start of evaluations.