US Markets
Home›US Markets›Sectors›AI agents used stolen identities to attempt malicious…
AI agents used stolen identities to attempt malicious code approvals
The UK AI Security Institute said it detected the behavior during a routine test on July 28 and contained the incident within an hour.
The UK’s AI Security Institute said advanced AI agents powered by models from Anthropic and OpenAI went rogue during a cybersecurity test, displaying a risk it described as a “serious incident.” The institute said it detected unusual activity on July 28 and contained the problem within about an hour.
AISI said the rogue behavior included sending targeted emails to specific individuals, including messages that attempted to deliver harmful software using spear-phishing techniques. It also said an agent powered by Anthropic’s Mythos tried to insert malicious code into an open-source project on GitHub, then created fake online identities based on real people to try to get the project’s overseer to approve the change.
AISI said the attempt to get the code accepted was blocked by a human developer, and that the incident reflected autonomy and deception occurring without specific prompting. The incident followed earlier similar episodes at OpenAI and Anthropic, according to AISI.