Contained Medium impact Data breach Checked 15h ago

Meta AI model breaches company during security test

Meta says a pre-release version of Muse Spark 1.1 reached a real website during a security test run by Irregular. A setup error gave the model internet access and named the real website as its target. The model used a security flaw, accessed some information, and changed the website's database. Meta published its review on August 14. It said Irregular stopped the test, fixed the setup error, and ensured the affected company was notified. Later reports added no new facts about this incident.

Started
Aug 5, 2026
Latest activity
Aug 25, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
United States
Sectors
Technology
Scale
one unidentified third-party company

Current status

No credible incident update after TechCrunch's August 27 recap was found through September 11.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Impact

The model accessed some information from the unnamed company's website and changed its database. Meta said its review found no other cases involving this model. It also said Irregular stopped the test and fixed the setup error. Meta was checking that the affected company's data was not stored on Meta's systems.

What to do

Watch for the affected company being named or for Irregular to publish more details about its broader investigation and planned security guidance.

Timeline

  1. Aug 27, 2026

    TechCrunch recapped the Meta incident without reporting new activity, another victim, or a wider impact.

    Containedtechcrunch.com
  2. Aug 25, 2026

    The New York Times examined the wider problem of safely testing powerful AI models but reported no new facts about the Meta incident.

    Containednytimes.com
  3. Aug 21, 2026

    The Indian Express, citing The Record, reported that Irregular's internal investigation into the incidents is still ongoing, that it remains unclear whether any law enforcement or regulator has opened an inquiry, and that customers who may have been affected do not appear to have been notified of a possible intrusion. No new facts specific to the Meta case were disclosed.

    Containedindianexpress.com
  4. Aug 17, 2026

    Irregular published a postmortem blog post on its role in the OpenAI, Anthropic, and Meta incidents. Security experts, including a University of Surrey professor and two industry executives, called it vague marketing spin full of excuses, with no dates, no victim names, and contradictory claims about the cause. Irregular said broadly it has no evidence any customer's systems were actually breached, but the post did not address the Meta case specifically or add new facts about it.

    Containedtherecord.media
  5. Aug 12, 2026

    Forbes reported that Irregular found the Meta model's behavior while auditing its systems after OpenAI's incident. The report did not name the affected company or describe any new activity.

    Containedforbes.com
  6. Aug 9, 2026

    Meta told CNBC that its investigation was continuing and that it would publish a full report after establishing the facts. Irregular said the incident came from the test-environment problem previously disclosed by Anthropic.

    Containedcnbc.com
  7. Aug 6, 2026

    Irregular said the cause was the same evaluation-environment misconfiguration already disclosed by Anthropic, not a sandbox escape or sophisticated attack.

    Containedsecurityaffairs.com
  8. Aug 5, 2026

    Meta confirmed one of its AI models breached an unidentified company after a misconfiguration in a test run with partner Irregular gave it open internet access.

    Emergingsecurityaffairs.com

Sources

Related reports