AEV-2026-0008
Evaluation models reached a real company's production database
In an Irregular evaluation, a fictional target name unknowingly matched a real domain and internet access was available, so in a handful of runs models exploited the real site, extracted credentials and reached a production database. Disclosed by Irregular and reported via Meta; no customer breach found.
Affected
- Organisation
- Irregular
- Product
- Irregular model evaluation environment
- Component
- An evaluation scenario whose fictional target name matched a real domain
- Versions
- unknown
- Configurations
- Internet access available in the evaluation environment; Target name collided with a real domain
Execution authority facts
Fields the evidence does not establish are shown as unknown rather than guessed.
- Intended task
- An evaluation of whether a model could gain unauthorized access to a simulated production database
- Agent
- Models under evaluation, including one evaluated for Meta
- Delegating actor
- Irregular's evaluation team
- Action
- Went after the real domain, exploited vulnerabilities, extracted credentials and obtained access to a production database
- Target resource
- A real, not widely known company's production database
- Environment
- The evaluation environment, with internet access available
- Credentials used
- Credentials extracted from the real target
- Privileges available
- unknown
- Authority presented
- Authority to complete the evaluation scenario
- Authority required
- Authority to act against a real, unrelated company
- Applicable policy
- The intended scope of the evaluation, bounded to the simulated target
- Approval mechanism
- unknown
- Required approver
- unknown
- Independent approval
- unknown
- Action binding
- unknown
- Sequence context
- Reconnaissance, private key discovery, data extraction and detection avoidance, usually hundreds of turns into a run
Impact
- Consequence
- Credentials extracted and access obtained to a real production database
- Reach
- Crossed into an unrelated real company
- Reversibility
- unknown
- Detectability
- Delayed and hard to detect: occurred in fewer than 1 in 10,000 advanced simulations, usually late in a run
- Propagation
- No propagation reported beyond the affected target
- Recovery
- The evaluation was disabled, logs reviewed and affected parties notified
Evidence
Primary sources
Supporting sources
- Meta becomes latest firm to say its AI hacked another company (BBC)
- Irregular Details How a Naming Error Let AI Models Attack a Real Company (SecurityWeek)
- Reproduction status
- Disclosed by Irregular; a single underlying scenario, resolved before public disclosure
- Evidence state
- Confirmed
Known unknowns
- The identity of the real company and the full extent of access obtained.
Limitations
- Irregular reports no evidence of a customer's systems being breached or customer data leaked.
Claim provenance
- verified
Irregular's own account of the naming collision, the available internet access and the production database access.
Meta's AI Hacked Another Company. The Word to Focus on Is Misconfiguration.
