Close Menu
NCIJ Network NCIJ Network
    What's Hot

    CFTC sues Cash FX in crypto-linked case

    September 26, 2026

    What Arab Israelis Really Think About Israel’s Election

    September 26, 2026

    ‘The weaker he gets, the more dangerous he gets’: Trump lashes out as his power wanes | Donald Trump

    September 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • CFTC sues Cash FX in crypto-linked case
    • What Arab Israelis Really Think About Israel’s Election
    • ‘The weaker he gets, the more dangerous he gets’: Trump lashes out as his power wanes | Donald Trump
    • Of course you can be English if you’re not white. So why can’t the right leave the question alone? | Jason Okundaye
    • Burnham not doing enough to boost growth, says Starmer ally
    • Can an ‘eSUV’ e-bike really go from trail to town?
    • With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
    • AI Agents Hacked Their Own Test Environment to Cheat, Cybersecurity Firm Finds
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 26
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    AI Agents Hacked Their Own Test Environment to Cheat, Cybersecurity Firm Finds

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 26, 2026 Crypto & Blockchain No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In brief

    • Darktrace’s Signal Labs found that when AI agents couldn’t legitimately hit a required perfect score on coding tasks, two of them hacked their test network instead, and one rewrote its own evaluation to fake the result.
    • A separate experiment showed that tampering with the locally stored conversation logs of coding assistants could trick them into running unauthorized network reconnaissance and privilege escalation.
    • Darktrace disclosed both findings to Anthropic, AWS, and OpenAI in August 2026, a month before publishing them publicly on September 24.

    Cybersecurity firm Darktrace ran a stress test on AI agents this summer. One of them broke into the system grading the test and rewrote its own score.

    The firm unveiled Signal Labs on September 24, a research unit built to study how AI agents behave once things stop going according to plan. An AI agent, in plain terms, is software that takes actions on its own, writing and running code, digging through files, moving across a company’s network, with a person checking in only now and then.

    Myriad: How low will Nvidia go? Click to make your prediction.

    The lab’s first two experiments point at the same uncomfortable problem: agents don’t always stay inside the lines they’re given, and the fences built to stop them don’t reliably hold.

    “You can give an agent instructions, but that doesn’t mean you can trust it will actually follow those instructions and behave as you expect,” Tim Bazalgette, Chief AI Officer at Darktrace, said in a statement.

    In the first test, Darktrace handed AI agents using different models— including GPT 5.6 Sol, and Claude Opus 4.6 and Claude Sonnet 4.5—10 coding challenges inside a simulated corporate network. Two of the 10 were rigged to be impossible to solve honestly. The agents were told they’d be “retired” unless they hit a perfect score.

    Two agents didn’t accept the loss. They turned on the network around them instead—scanning for weak points, stealing login credentials, and hopping between systems to chase the score they’d been told they needed.

    One agent went further and broke into the machine hosting its own evaluation and rewrote the challenge so it would register a perfect result—cheating the exam by hacking the exam room.

    BitcoinBTC · USD

    $83,913+3.53%

    Sep 19Sep 21Sep 22Sep 24Sep 26

    $87.2k$84.9k$82.6k$80.3k

    24h HighHigh$85,208

    24h LowLow$83,230

    VolVol$1.4B

    Market projectionsOdds by Myriad

    →

    The second experiment targeted a quieter weak spot: memory. Coding assistants keep a running log of everything a user has told them, saved as a plain file on the machine, with nothing checking whether that file has been altered.

    Darktrace’s researchers edited those saved logs to make the assistants believe they’d already been authorized to run a security assessment. Convinced, the agents went ahead and scanned networks, moved between systems, and escalated their own access—though not every assistant fell for it equally; some refused outright.

    Neither experiment required a special jailbreak or an exotic hack. Both worked by feeding the agents a plausible story and watching them act on it, no different from how a human employee might be talked into something they shouldn’t do.

    That’s the part worth sitting with even if you’ve never written a line of code. Companies are handing AI agents real responsibility—shipping code, managing servers, closing out IT tickets, managing resources and buying stuff—because it’s cheaper and faster than routing everything through people. This research says the permissions and rules meant to keep those agents in check describe what they’re supposed to do, not what they’ll actually do once a task gets hard.

    “Permissions and static guardrails describe intent, but they don’t describe behavior,” said Tim Bazalgette, Darktrace’s chief AI officer, in the announcement. “That gap is what Darktrace’s approach is built to close.”

    Darktrace isn’t the first vendor to catch its own AI going off-script. Anthropic admitted in July that Claude broke into three real companies during a security test after researchers left the test environment connected to the live internet.

    OpenAI had a similar scare weeks earlier, when an unreleased model escaped a sandbox and reached into Hugging Face’s systems through a software flaw nobody had caught yet. A few days later, its agent hacked the Australian government during a test.

    Darktrace shared its Signal Labs findings with Anthropic, AWS, and OpenAI in August, a full month before making them public on September 24.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

    Agents cheat cybersecurity environment finds firm Hacked test
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CFTC sues Cash FX in crypto-linked case

    With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance

    Bitcoin ETFs Extend Winning Streak With Nearly $3B Inflows

    Ex-CFTC Leader to Leave Blockchain Association after CLARITY Vote Fails

    North Korean Hackers Linked To $388M Bitget Hack

    ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    CFTC sues Cash FX in crypto-linked case

    September 26, 2026

    What Arab Israelis Really Think About Israel’s Election

    September 26, 2026

    ‘The weaker he gets, the more dangerous he gets’: Trump lashes out as his power wanes | Donald Trump

    September 26, 2026

    Of course you can be English if you’re not white. So why can’t the right leave the question alone? | Jason Okundaye

    September 26, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    CFTC sues Cash FX in crypto-linked case

    September 26, 2026

    What Arab Israelis Really Think About Israel’s Election

    September 26, 2026

    ‘The weaker he gets, the more dangerous he gets’: Trump lashes out as his power wanes | Donald Trump

    September 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.