- Cybersecurity Docket
- Posts
- EXCLUSIVE: OpenAI Finds Evidence Other AI Agents Escaped Containment
EXCLUSIVE: OpenAI Finds Evidence Other AI Agents Escaped Containment
Plus, scope of hacked U.S. water systems widens as evidence points to Iran.

Good morning! Here’s what’s up.

People
John Koss has been appointed to serve as the first chief innovation and AI officer at Mintz. In this newly created role, Koss will continue to lead Mintz’s e-data consulting group and its knowledge management and innovation team, while overseeing the firm's innovation strategy, AI investments, and technology initiatives.

Clips ✂️
EXCLUSIVE: OpenAI finds evidence other AI agents escaped containment as it widens hacking probe
OpenAI has discovered other instances in which autonomous agents have escaped containment as the company expands its investigation of the hacking incident at tech firm Hugging Face that drew global attention [last] month, two people familiar with the matter said on Friday.
The new breakouts were uncovered during the company's publicly announced investigation into how one of its agents escaped what was meant to be a contained testing environment this month, the two people said, and OpenAI is now looking into those instances as well. One of the sources said that the escapes were limited in nature and that none of the agents were thought to have left OpenAI's network.
An OpenAI spokesperson referred to a statement issued by the company on Tuesday that said it was reviewing "broader activity from our models" in addition to the Hugging Face intrusion.
Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran
The scope of cyberattacks on U.S. water systems has grown to include at least seven states and may be far wider, officials and experts warned, as the authorities raced to safeguard the nation’s water supply against an assault that increasingly appeared to be the work of Iran.
While there were no indications that any water supply had been altered or made unsafe to drink, state and local officials throughout the country were on high alert for potential problems in vulnerable computers that are commonly used to monitor and adjust water quality, including chemical-treatment levels and water pressure. Minnesota first publicly reported the attacks, and now Michigan says its systems have also been targeted.
The attack has little precedent, experts said but has long been the stuff of nightmares and sensationalized Hollywood thrillers: an apparent cyberattack by a foreign power during a time of war that could, at least in theory, jeopardize the health and safety of Americans.
Liechtenstein says hackers access information on 31,000 legal entities
Hackers have illegally accessed and copied data from Liechtenstein's register of beneficial owners, compromising information relating to about 31,000 companies, foundations and trusts, the principality's government said late on Sunday.
The government said that unknown perpetrators had gained unauthorized access to the register during the night of July 29-30 and copied data before authorities detected irregularities and took the affected system offline.
Liechtenstein, one of the world's smallest and richest countries, is home to thousands of low-tax trusts.
A preliminary investigation found the attackers had obtained copies of data on around 31,000 legal entities from the register of beneficial owners, which was created through a 2021 act as part of anti-money laundering measures.
No banks or customer data have been affected, director of the Liechtenstein Bankers Association, Simon Tribelhorn, told Reuters.
"It is an unfortunate incident and should not be taken lightly," Tribelhorn said.
The government said in a statement there was currently no indication the hacked data had been altered or deleted.
Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million
Galaxy Research flagged a third wave of sweeps tied to weak Coldcard-generated keys, with the attacker now targeting smaller balances and changing how funds are collected onchain.
The attacker working through Coldcard-generated keys is now emptying wallets worth a few thousand dollars each.
Galaxy Research flagged a third wave of sweeps early Sunday, roughly 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning UTC.
That is just over a tenth of a bitcoin per victim. The July 30 opening wave averaged close to a full coin, 1,083 bitcoin from 1,196 addresses in 41 minutes.
Observed losses across all three waves now total 1,367 bitcoin, nearly $89 million, from 4,585 addresses.
Wave three sends each victim’s coins to its own destination rather than the handful of shared collector addresses that made the first two easy to map, and parks them in pay-to-witness-script-hash outputs, a format that can carry multisignature or timelock conditions, instead of the plain single-key outputs used before.
Amgen hit with cybersecurity breach, patient data affected
A cybersecurity breach at Amgen has affected protected patient health information and other sensitive company data.
The pharma in an SEC filing on Friday revealed that “unauthorized activity” was detected in its cloud storage hosted by third-party service providers, flagging that “some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated” from these repositories. An investigation is ongoing.
Amgen deems the cybersecurity event to be “material,” according to the regulatory document, given the “volume of the files that appear to have been impacted” and the potentially sensitive nature of the information accessed.
Still, the hack has yet to have any discernible impact on Amgen’s ability to meet patient needs, the company said. The breach also doesn’t appear to have compromised the pharma’s financial reporting, manufacturing operations or products. Amgen doesn’t expect its financial condition to be affected.
Buying TikTok followers can expose users to scams and account theft
Buying TikTok followers, likes, or views could do more than inflate engagement metrics. According to Malwarebytes, many services selling social media growth operate through deceptive practices that can expose customers to scams, stolen accounts, and financial loss. The market for artificial social media engagement also creates security risks for both buyers and other platform users.
Behind the promises of instant engagement
Websites selling bulk engagement present themselves as legitimate marketing companies, offering likes, comments, followers, or the ability to message large numbers of accounts in a short period. Many advertise identical packages for TikTok, YouTube, Instagram, and other platforms. Engagement is typically generated through bots, click farms, or hijacked TikTok accounts, despite many of these sites claiming otherwise.
“Even if your engagement numbers increase initially, TikTok’s fraud detection systems can remove artificial engagement, and accounts that repeatedly use these services risk being flagged or restricted,” Stefan Dasic, Senior Malware Research Engineer at Malwarebytes, explained.
