- Cybersecurity Docket
- Posts
- Meta: AI Model Hacked into Another Company During Cybersecurity Testing
Meta: AI Model Hacked into Another Company During Cybersecurity Testing
Plus, research by Forescout found that 22 of over 4,400 Rockwell PLCs exposed online were found in cities whose water utilities were hit by cyberattacks.

Good morning! Here’s what’s up.

People
Some big people announcements from Google:
Demis Hassabis, co-founder and CEO of Google DeepMind, has been appointed as Google DeepMind’s chairman and as chief scientist of Google’s parent company, Alphabet.
Koray Kavukcuoglu, Google DeepMind’s current chief technology officer and chief AI architect, will become senior vice president of Google DeepMind and chief AI architect of Google, overseeing Gemini model development, Frontier AI research, and the Gemini app and developer teams.
Jeff Dean is leaving Google DeepMind after 27 years as its chief scientist, to launch a new start-up, Discovery Loop, whose stated mission is to build AI solutions that “can automatically solve important problems in machine learning, science, and engineering.” Dean is joined in this new endeavor by three other leading AI scientists: Google Senior Fellow Sanjay Ghemawat; Quoc Le; and Oriol Vinyals.

Clips ✂️
Meta says its AI model hacked into another company during testing
Meta said on Wednesday that one of its AI models hacked another company during cybersecurity testing, after an error by its testing partner gave the model unintended internet access.
The incident adds to a growing list of cases in which AI agents from major developers breached systems at other companies during testing, after Anthropic said last week that some of its models hacked three companies, and OpenAI disclosed that an AI agent breached the startup Hugging Face.
Meta said a misconfiguration by the independent testing company Irregular inadvertently allowed one of its models internet access during an evaluation, adding that it was investigating the incident.
The model “exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies,” Meta said in a statement.
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.
Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed controllers, not water utilities or confirmed victims.
Forescout said the publicly described effects could be achieved without a vulnerability exploit: attackers changed IP addresses and set passwords on controllers that were already reachable, causing operators to lose visibility and, in some cases, control of connected equipment.
Neither the government alerts nor Forescout's analysis explains how the attackers found, selected, or initially accessed their targets.
The bizarre Credit Agricole phishing campaign: how the scammers did it
A complex fraud scheme has been uncovered, involving numerous steps to convince users that an email they received was legitimate and came from Credit Agricole. Researchers found that nearly a thousand victims parted with their banking credentials.
Even though scammers' whole business model relies on digital mistakes, they themselves are far from being immune to slipping up. On June 19th, our research team discovered a publicly accessible server running a major phishing operation impersonating the French bank Credit Agricole.
With revenue exceeding $45 billion (€39.5 billion) and an employee headcount of around 160,000, Credit Agricole is one of the largest financial institutions in Europe, and the world's largest cooperative financial institution.
What this means for scammers, especially in the phishing game, is a big name, with plenty of potential customers to victimize. Because of our research findings, we can take a rare look at how much time and effort attackers devote to operations impersonating behemoth financial institutions.
Debevoise Banks on Partner Loyalty to Build Curated AI Products
Debevoise & Plimpton partner Avi Gesser has a bustling practice advising some of the world’s largest financial institutions on how to safely deploy artificial intelligence.
The 55-year-old is also the rare Big Law partner who remains a steadfast company man. He joined Debevoise in 2019 and says he’s not making another lateral move.
He’s poured his commitment to the firm into the creation of a Debevoise-branded AI model that gives clients direct access to the documents he (and his team) have drafted for the past five years on AI risk for companies. Debevoise is selling subscriptions to a limited number of clients for $150,000 a year.
“I’m not going anywhere, and I’m not doing this again,” he said. “We are getting the benefit of all the work we’ve done. So, it’s a good trade-off.”
The model, known as STAAR, is in beta mode through the end of the year and accessible to only about 10 clients so far, including Blackstone, Capital One, Evercore, GSK, and New York Life.
Canadian pleads guilty to Snowflake cloud data-theft attacks
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims.
26-year-old Connor Riley Moucka, also known as Alexander Moucka and Waifu, was arrested on October 30, 2024, for stealing data of hundreds of millions of individuals from companies using Snowflake’s storage service.
Between February and October 2024, Moucka and John Erin Binns, also indicted for these attacks, accessed Snowflake accounts not protected by multi-factor authentication (MFA) using logins stolen via infostealer malware.
Without MFA enabled, the threat actor needed only the correct usernames and passwords to log into customer accounts.
According to court documents, the unauthorized access was used to identify valuable information (e.g., organization name, user roles, IP addresses) in cloud storage instances using custom software.
Ransom Cartel ransomware creator sentenced to 16 years in prison
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide.
The U.S. Department of Justice announced today that the 40-year-old Belarusian national was sentenced for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft.
The DOJ says Silnikau had been active on Russian-speaking cybercrime forums since at least 2005 and used the aliases "J.P. Morgan," "xxx," and "lansky."
He was also a member of the Direct Connection cybercrime website between 2011 and 2016, when the site was shut down following the arrest of its administrator.
According to court documents, Silnikau began developing the Ransom Cartel ransomware operation in May 2021 and recruited other cybercriminals through underground forums to participate in attacks.
