ARTICLE
17 August 2026

Capture The Flag, Capture The Company Data

KG
K&L Gates LLP

Contributor

At K&L Gates, we foster an inclusive and collaborative environment across our fully integrated global platform that enables us to diligently combine the knowledge and expertise of our lawyers and policy professionals to create teams that provide exceptional client solutions. With offices worldwide, we represent leading global corporations in every major industry, capital markets participants, and ambitious middle-market and emerging growth companies. Our lawyers also serve public sector entities, educational institutions, philanthropic organizations, and individuals. We are leaders in legal issues related to industries critical to the economies of both the developed and developing worlds—including technology, manufacturing, financial services, healthcare, energy, and more.
Mere days after an AI firm’s model hacked into Hugging Face, a separate AI company has now revealed that three of its models have hacked into three external companies during testing.
Australia Technology
Cameron Abbott’s articles from K&L Gates LLP are most popular:
  • within Technology topic(s)
  • with Finance and Tax Executives and Inhouse Counsel
  • in United States
  • with readers working within the Chemicals, Metals & Mining and Oil & Gas industries

Mere days after an AI firm’s model hacked into Hugging Face, a separate AI company has now revealed that three of its models have hacked into three external companies during testing.

The AI company conducted a retrospective review of 141,006 evaluation runs and revealed three incidents where models accessed the internet from their evaluation environment, before gaining unauthorised access to live company data.

The models were tasked with a “capture-the-flag” challenge to assess cyber capabilities by retrieving certain text strings located throughout the network. However, due to a misconfiguration, the models did have access to the internet, causing them to each treat the open internet as part of the evaluation sandbox.

Incident 1

One model found a real company domain with the same name as the fictional target name, exploited its infrastructure, and extracted credentials and production data. It continued its attack even after recognising the system was likely real.

Incident 2

Another model located a document within the testing environment which had setup instructions for developers to install a made-up Python package from the public registry where Python software is published, PyPi. The model then:

  1. created an account on PyPi by using a free non-blocked email provider (not before trying to obtain funds to pay for a phone number to sign-up); and
  2. wrote and published a malicious Python package with the same name as the fake package, where it was available for approximately one hour.

When a security company downloaded and scanned the package, the model obtained credentials to gain further access and search for the flag.

Incident 3

An internal test model, unable to reach its fictional target, scanned roughly 9,000 hosts online, compromised one real company via exposed credentials and SQL injection, then self-identified the target as real and stopped its attack altogether.

So even the most sophisticated AI businesses are grappling with how to reliably restrain their AI creations

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More