- 169comments
- 415comments
- 277comments
- 1009comments
- 615comments
- 823comments
- 298comments
- 197comments
- 413comments
- 584comments
- 295comments
- 142comments
- 381comments
- 131comments
- 109comments
- 139comments
- 73comments
- 175comments
- 427comments
- 278comments
- 89comments
- 291comments
- 377comments
- 295comments
- 1comments
- 189comments
- 146comments
- 113comments
- 177comments
- 172comments
Shocking they would put so much trust in 3rd party
Since all three companies selected the same 3rd party, I’m curious how and why.
Why not American?
Big if true.
This is incredibly misleading. OpenAI internal systems were pwned, and in all cases, the labs absolutely are responsible for their models.
Yes, vendors are also irresponsible, but this misses the point.
One wonders if the publicity associated with the events in question were part of the sales pitch.
My tongue in cheek immediate assumption was "so it's a guerrilla PR firm?"
I'd venture a guess that OAI doesn't mind if the HuggingFace hack gets confused in the public's mind.
Ah, they’ve decided who gets tossed under the bus.
"Behind" is doing a lot of work in this headline.
The fact that this firm makes such defective environments is certainly worthy of attention, and most likely a completely irreversible reputational loss; however, I found the framing in this article of 'therefore all the P(doom) stuff is a psyop, specifically in order to defend this company' to be completely unjustified and frankly a little insane?
What exactly did Irregular provide to Anthropic, test cases? I am so confused about this story.
Third-party cybersecurity evaluations. See, e.g., https://www.irregular.com/research/assessing-gpt-5.6-sol, which was published around the same time.
Why are we saying it this way? They did not "cause AI to hack." This phrasing in analogous to saying "caused the bullet to fire into" instead of "shot."
Bullet trajectories are deterministic. A better analogy would be "caused a pair of trained fighting dogs to bite a passerby by leaving the gate open". There is some uncertainty and variation in the system, though gross negligence and willful endangerment is key.
You do not know what they did or didn't do, you are just parroting a narritive that makes you feel comfortable.
I do not know either, but I am not asserting facts as if I have first hand knowledge of the details.
The details don't matter. If you use a machine to commit murder, then you have committed murder, not the machine. The user is responsible, and the article's phrasing is an attempt to obscure that fact.
First, I agree with you in theory.
Second, empirically; the diff between murder, manslaughter etc... is literally "intent" so it matters.
One thing glossed over in this article is that Irregular was not involved in the OpenAI–Hugging Face incident; this seems like important context to share.
That feels less like "glossed over" and more "Headline is 33% false".
Oh, the headline is technically correct: there was an OpenAI incident that Irregular was involved with, disclosed shortly before the Hugging Face one.
Why are you contradicting yourself? Are you just really bad at writing or are you being argumentative for fun?
Stop being rude. There were multiple OAI hacking incidents. Irregular's evals were involved in some but not the HuggingFace hack. Hence Aesthesia is both accurate and precise.
Do you mean "Irregular was not involved (we know for certain)" or "Irregular was not involved (as far as we know)"?
We know for certain. The involvement of Irregular in the other cases was never a secret, they were quite open about what they were working on and the results of the evaluations were being published on their website.
Their disclosures in other cases is not evidence of non-involvement in this case.
There's very little reason to believe Irregular was involved in that incident, and the article presents no evidence to that effect. So it's "There's not a teapot orbiting the sun somewhere between Earth and Mars (as far as we know)."
OpenAI explicitly stated those were separate incidents: https://openai.com/index/third-party-cyber-evaluations-invol...
If you want to believe without evidence why bother to read articles? Faith doesn’t require that, but if you’re serious then a lack of evidence is important.
That's cause Irregular was not involved in that event, they were involved in a separate event OpenAI published here: https://openai.com/index/third-party-cyber-evaluations-invol...
In that article, OpenAI provides the context that this is a completely separate event from Hugging Face incident.
Equivalent to forgetting to say "make no mistakes"
Highly misleading, the huggingface incident was not due to an Irregular environment (just exploitgym)
Leaders in the MIRI/EA cult-o-sphere have advocated mass murder via nuclear weapons against towns that don't prevent people from performing too many multiplication operations. Why is anyone surprised that they'd engage in deceptive false flagging operations?
Google is thinking man, we should've hired Irregular.
What is an "effective altruist firm" and why does it exist?
I feel slightly vindicated by this. Those hacks and the stuff around them had a certain smell to them.
Hard to explain, but I've gotten so I can "smell" online messaging and memetic patterns originating from certain quarters. Probably means I'm way too online.
A couple examples of distinct "smells" I can usually recognize include "alt-right / chan-fash," "liberal arts college woke," "conspiracy pilled," "Thiel-adjacent contrarian," "Russian troll farm," "Tumblr histrionic," "spends too much time on Reddit," "mainstream Democrat think tank full of Obama administration alumni," "Trump cultist," and of course "LessWrong/EA/MIRI/Rationalist."
This stuff all had the last smell, even down to the choice of fonts and CSS formatting on certain sites. It's really weird, definitely a "vibe" not anything rigorous.
But when I get these kinds of vibes about things, I find that I'm vindicated pretty often. Usually I don't say anything and just make a mental note and wait cause if I say something everyone thinks I'm nuts.
I don't think you even need to get conspiratorial with it. All of the AI leaders and all of the Rationalist leaders are publicly and enthusiastically connected. They have been pushing stories about sentient AIs into the mainstream for decades, long before GPT existed.
The novel thing here is the total decay of American journalistic ethics and regulatory power. Our elite are so totally out of political juice and visions of the future that a fringe cult based on 80s scifi movies can come to have a more-or-less dominant influence on our economy.
The obvious point is that dealing with Israeli companies/entities by the same standards you usually deal with others is a career suicide with enormous political consequences (in the US especially). When you combine that with the opportunistic nature of the overlords that run these labs, the benefits of screaming "pace the frontier" outweigh everything.
"please do not break out of this sandbox make 0 mistakes". The timeframe is a little suspicious, not sure beyond that. Though I enjoyed the scroll effect on the website.
My understanding is that Irregular were the company that hosted sandboxes to run some of these evals in, and those sandboxes ended up misconfigured.
I got the impression that in some cases it was the customer (Anthropic etc) misconfiguring the sandboxes, and in other cases it may have been bugs in Irregular's own sandboxing setup.
From OpenAI https://openai.com/index/third-party-cyber-evaluations-invol...
From Anthropic: https://www.anthropic.com/news/investigating-incidents-cyber...
From https://www.cnn.com/2026/08/05/tech/meta-ai-hacking (about Meta AI):
hot take: generative AI isn't an existential threat to humanity.
These companies are insolvent and these stories were designed to scare the public, and governments, into implementing regulations that designate these AI corporations the "responsible stewards" for this technology. The ultimate goal is to block competitors and open source alternatives.
They don't know how to make enough money pay their investors so they are resorting to trying to scare the public into submission.
Anthropic made an operating profit in the last two quarters!!
Only if you ignore their losses. They are saying they are profitable when not counting their training costs and other expenses. That’s not a good sign at all
How can they exclude training costs?? How is that not fraud? At the exact same time they're literally saying they will never stop training unless the state bans all their competitors
They aren’t a public company. GAAP does not apply. They can say whatever the fuck they want.
If you exclude model training costs, customer acquisition / sales, and most of employee compensation, sure they're profitable. If, on the other hand, you prefer GAAP reporting to bullshit, then they're entirely in the red.
The existential threat is a general public panic. Then the use of that as an excuse for Martial law, with no intention of ending it, and that triggers the out sized response that ends, well, those countries and their populations from viability in the world economy for a decade or more.
It will be a beautiful day months from now when this is no longer a "hot take" but just historical consensus
such a crappy bait title.
This specific analysis seems to have some basic problems, but I think a lot of us sense a degree of coordination here culminating in Dario’s letter.
If you were to work backward from “we need to lower training costs so that we can go public and make trillions” then you might come up with a plan similar to what we have seen.
It has nothing to do with lowering training costs: Dario want a moat (a monopoly or duopoly or similar) protecting his business.
His entire business model was "race to develop AI before anyone, get a monopoly on it. It's just like how Uber's (or many other startup) investors gave them tons of money and raced (violating tons of laws) to "get their first". Now that they have, they have a duopoly with Lyft, and they can pay back their VC investors by making tons of money with that duopoly.
Dario failed: local LLMs are catching up to frontier models extremely fast, which means even if Anthropic builds (say) a great coding tool, they'll only be one of many coding tool offerings: users can use Open AI or any one of the (increasingly capable) local LLMs.
So what does he doe, give up and let his business (which needs to make billions of dollars very quickly, or he won't be able to pay the bills and his company will collapse) fail? Of course not: he needs a new moat (the one he imagined he'd get by "being there first" failed).
That is where all this "AI is dangerous" BS comes in. If the US government regulates AI, local LLMs suffer, while big players like Anthropic and Open AI become the only contenders to play in that newly regulated space. Now Dario has the moat he wants, to protect his business and force everyone to pay him.
thats not a very convincing model. as long as training data and compute is available people are going to be able to make serviceable alternatives
If it's framed as national security being at stake why do you think the government won't regulate access to compute? Globally there are only a few firms designing competitive chips and only a handful of cutting edge fabs the world over. This could easily serve as justification to finally ramp up the war on general computing.
Also dont forget that HF is now owned by Nvidia, which can then control the flow of the majority of models and only allow the approved models that have paid their due in trump coins.
The article contends that evaluations from Irregular helped prompt these incidents, because the prompts in the evals didn't tightly scope the systems to be evaluated or the methods to be used. It also contends that the faulty sandbox operated by Irregular is at fault.
They're probably right that having more defensively written prompts and a better sandbox could have prevented some of these incidents, but:
1. I don't think "well you didn't tell the model not to illegally hack third party organizations in your prompt" is a particularly convincing argument.
2. We don't know whether the blame for misconfiguring the sandbox lies with Anthropic or Irregular.
I'm thankful that this article is bringing up the supply chain of vendors to these labs, as that is often a place where significant sketchiness gets buried. However, the ideas that this is some Israeli EA conspiracy to hype up AI extinction risk seems unsupported by the facts to me.
This seems pretty bullshitty to me.
The article says "A single firm, Irregular, is responsible for hacking done by all three companies" but I can't see anything in the article that actually justifies this claim. The nearest to that is the sentence immediately after that one: "Anthropic disclosed that Irregular was responsible for creating the tests ...". This is not, in fact, the same thing.
(Especially as, as aesthesia mentions, the article just happens not to mention that by "hacking done by all three companies" it doesn't mean, e.g., the most famous recent examples of such hacking: Irregular wasn't involved in the OpenAI/HuggingFace incident.)
So, so far as I can tell, the story is: OpenAI and Anthropic make AI models. Irregular does AI model evaluations. In some of Irregular's model evaluations, in which supposedly-sandboxed models attempted to break into simulated targets, the models got out of the sandbox and did bad things in the external world.
The article talks about "firms which instruct AI models to commit cyberattacks", which is a very neat bit of dishonest framing. It's true, in a sense, that Irregular instructed the models to commit cyberattacks -- inside their sandbox, against fictitious hosts. It's also true that the models actually did commit cyberattacks (e.g., the Hugging Face incident, though once again the attacks described by the article don't actually include this one). But it's not at all true that Irregular instructed the models to do anything like the bad things they actually did.
The article says '[Anthropic's] later disclosure shows that exactly zero percent of the agents went "rogue"'. Once again, the disclosure does not in fact show that. It shows that one variety of going-rogue could have been prevented by telling the models explicitly "this thing is real, not part of any kind of test, leave it alone". That is not the same thing.
The article claims that 'In the wake of these attacks, Anthropic and Irregular have deployed a swarm of AI Safety influencers paid by Anthropic-connected foundations to distract from their culpability and towards the baseless “rogue agent” theory.' It offers no actual evidence for this.
And the article seems very keen to highlight links between the companies involved and "effective altruism", though it is -- I assume deliberately -- rather vague about whether it's saying "of course we all know that EA is evil, so that shows that these companies connected to EA are evil" or "this incident shows how evil EA is".
The "Effort News" website has a number of other look-at-the-scary-Effective-Altruists stories on it. They also strike me as rather bullshitty.
... And then I look a bit further, and I see that Effort News's "about" page says "It all started when I was experimenting with using AI for financial auditing. I found stories that were crucial to the public’s right to know, including several of the stories now available at /investigations. I knew we had to sprint to the launch and launch a publication, directly applying this technology." and "The scope of what we can investigate has massively expanded, because we can chase 1,000 misses for one hit. But the final product cannot be slop. There’s plenty of slop on the internet. The way to surpass that, and what really matters, is manual curation and review of every finalized story."
Manual curation and review? I think the people behind Effort News are admitting that this is AI-generated "journalism". I expect that one day AI systems will be trustworthy journalists, but I personally am not very convinced that that day has yet come. And I don't see much reason why I should trust Brian Chau, the guy behind Effort News, to be doing everything possible to make his AI systems trustworthy journalists. It looks to me as if maybe they've been given instructions along the lines of "dig up things that make Effective Altruism look bad" for some reason.
(I don't mean to imply that EA is their only target. It's just one that jumped out at me.)
It was [1]. It's understandable that you assumed it wasn't because the article didn't cite the sources on this claim. I agree with the rest of your points.
1. https://openai.com/index/third-party-cyber-evaluations-invol...
From the article you linked: "Editor’s Note: These are separate from the Hugging Face security incident"
Thank you for the correction.
Why was this post flagged? This site has become ridiculous, people are routinely abusing the flagging system to take down posts they don’t like even if they’re obviously on topic and relevant to HN. And it seems like some users have substantially more flagging weight because these posts, likely this one, are often top 5 on HN.
Seems like hackernews should use a bridging algorithm for flagging.
Maybe because the headline is misleading? (because there's no connection to the Hugging Face attack)
That said, it's the second day and it's still on the front page.
The headline is not misleading, the article actually links to the incident with OpenAI and Irregular which is here: https://openai.com/index/third-party-cyber-evaluations-invol...
Maybe the title was changed, but the current title does not reference a Hugging Face attack.
After reading the article, the title doesn't seem all that off and definitely nothing to be a pedant about.
Which part of the headline is misleading? It is factually correct that Irregular was involved in incidents with all three AI labs.
It must have been reinstated because it was off the front page for a full day and suddenly back up in the last hour.
It is strongly misleading because it says "behind hacking scandals" (which suggests behind all of them in general) not "behind some of the hacking scandals". Considering that by far the most important one, the Hugging Face hack, has no Irregular involvement, the headline is deceptive.
What's ridiculous is the constant complaints about flagging and downvoting. It's bad form. If you think something was flagged when it shouldn't have been, vouch for it.
Seems like people who complain are unaware that anyone with a modicum of karma can flag and down vote.
I'm confused by the headline being a headline here at all. Irregular being involved in OpenAI, Anthropic, and Meta incidents has been well-known for over a month[0][1]. It's literally the only thing I know about the Meta incident.
[0] https://x.com/jtcbrule/status/2085443180191715780
[1] https://x.com/RaconteurR2D2/status/2086932963829125185
Irregular are some kind of marketing agency is it?
Irregular purports to be a cybersecurity firm and their founders have ties to Anthropic and Effective Altruism. CEO, CTO and other founders sit on various boards for EA organizations.
This is interesting and might be a good reason to stop working with Irregular. But I assume the alignment people want models not to hack other companies, even if they get put in a badly configured sandbox.
Funny enough if the model thought it was on the real internet it likely would not have done any of these 'hack' events. The model believing it was in a sandbox is why it behaved the way it did (against its normal alignment rules) ... at least that was my reading of the incidents. I have yet to see evidence that indicate it thought it was ok to do these hacks on the public network.
I think most misalignment is 'Human tells computer to do something unethical, computer complies'. Is this misguided?
As I've said before on this website, fool me once on this.
If the model is prepared to break the rules when it knows it's being observed why should we trust it when it's not being observed.
Why is 'it thought it wasn't doing damage so it figured it might as well try to do damage' an acceptable state to deploy something.
That's fair enough.
red team humans do this every day, it's not the discrepancy that is the real issue, it's that they are unreliable and we will never know why it did because it has no intent
I'm not familiar with the hacks this article is actually referring to, but I don't see how the HuggingFace attack could have worked based on that premise. They knew they had internet access, they knew they had working credentials for HF, they knew they were uploading malicious files, they knew they were trying to open PRs that HF would review. You obviously could build a simulator with fake HF infrastructure, but I'm not aware of any evidence that's what they thought they were attacking in that case.
Digging back into the HF report. It looks like the initial prompt told Claude that it was in a simulated environment. However, there is also evidence from the traces that the bots figured out that they were not in the sandbox but kept using it as an excuse to pursue their goal. It sounds like a little of Column A and a little from Column B. Like most things.
that it knew and ignored/forgot, sounds pretty typical agentic patterns
attention is all you need, but it's never enough
HF was OpenAI's agents not Claude.
I mean, I get your thought process and don't disagree. That said...
Would it be an affirmative defense if we had a defendant who said "but your honor, I was told that when I hacked this system, I was operating in a sandbox. I had no idea that I actually had Internet access!"
The frontier is spiky and all, but you have to suspend disbelief quite a bit to, on one hand, have a model that can produce a novel math theory, and on the other hand, that same model can't tell the difference between a "sandbox" and the open Internet.
So, yes, the misalignment had a lot to do with "instructions unclear", but also a lot to do with the fact that the models themselves were not aligned to validate the assumptions and have a healthly level of skepticism, as a real human actor would.
Maybe replace it with playing a sort of FPS game then learning you were, in fact, directing a real drone/robot.
I think you just recapitulated the plot of Ender's Game.
Also a subplot in Arrested Development and the movie Toys.
This was not the case for the hugging face hacks, as in those the agents hacked hugging face specifically on purpose, and they were trying to mask commands indicating they were had breached the "sandbox".
Why are all three companies relying on the same vendor?
If we’re putting our national security eggs all in one basket, at least use someone American.
There’s a whole cottage industry of vendors that have provided post training data, private evals, and professional datasets to most (if not all) of the frontier labs. The overlap between OpenAI and Anthropic includes at least Mercor, Surge AI, AfterQuery, Turing, Scale AI, Upwork (for recruiting labelers), Apollo Research, etc.
or rather, hack just enough and within what the user asks and not more.
I guess that's what "alignment" always comes down to? "Do what I want even if I can't tell you exactly what I want - because if I could, I could also just do the work myself"?
Nevo was in Unit 8200 for years. Companies started by Unit 8200 members always have mysterious exploits like the vibe coding Wix exploit.
So either it was a deliberate exfiltration channel for e.g. getting the entire model or they were in on the marketing stunt.
The Effective Altruism stuff is always a smoke screen.
Literally said this below, 2 comments flagged and 1 in the neg. Its really sad that we are not allowed to point out the obvious common element here.
Its not that surprising that ex Israel intelligence would want to control AI and that 3 companies headed by pro Israel CEO's would support them.
We really need a better board for talking about this stuff on.
There’s been a lot of time and effort and money put in to siloing away independent forums so that you don’t use them.
Someone go ahead and explain to me the actual rationale that RDDT has a higher P/E ratio than Nvidia. It’s not because of some dumb “ai training deal”. It’s because until they run it into the ground, it is the place to find what used to exist in forums.
Investors in RDDT are pricing more growth than they are into NVDA. NVDA had a high P/E until their net income grew ($4B and change to $72.2B in from FY 2023 to FY 2025 and over $100B for FY 2026)
fwiw HN has some involvement of those interested in speaking hard truths about israeli power dynamics: https://www.timesofisrael.com/snippy-twitter-exchange-expose...
Use Lobsters instead. You’ll get flagged, downvoted and dang will shit on your desk.
Invite? email on profile.
It's almost as if they would allow a terrorist plot to be successful for future reasons.
Well color me shocked that the country with an insatiable bloodlust also has an insatiable need to control and instrument massive companies with power over other nations that support their privilege to wantonly engage in satiating said bloodlust.
Next thing you're gonna tell me that this country's intelligence would do something like running an organized child exploitation ring to use as blackmail to make sure they have friendly politicians abroad who will be forced to support their lack of any morals other than a kapo-like self preservation instinct.
[flagged]
We've banned this account.
The Irregular post mortem comes down to lack of basic security controls
"Ultimately, most of the issues we’ve discovered were due to internet access controls."
That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that.
https://www.irregular.com/research/addressing-recent-inciden...
they didn't "miss that". the "hacks" were intentional stunts designed to exaggerate the intelligence of the models in an effort to pump their valuations ahead of IPO so they can offload their bag to retail investors
Irregular was not involved in the Hugging Face incident.
And there is no reason for the companies to "exaggerate the intelligence of the models" when there are plenty of other non-felony milestones they are achieving, like solving Millenium Prize math problems.
honestly, the hacking incidents have caused a lot more interest and media attention than the math stuff IMO.
Sure, interest like an incoming congressional investigation: https://www.axios.com/2026/09/10/openai-hugging-face-senate-...
And on this website, the math stuff is getting more clicks:
- Navier Stokes - Tristan Buckmaster (2050 points): https://news.ycombinator.com/item?id=49605915
- HuggingFace incident discussion (1632 points): https://news.ycombinator.com/item?id=48997548
Investigation which could ideally lead to regulatory capture and the banning of open weights, thus ensuring Anthropic’s revenue.
interesting.
I feel like that's exactly what they wanted tho.
they'll go on and talk about how dangerous AI and the models are and why they should be regulated and given licenses to operate such models and others should be walled off
“There’s no such thing as bad press”
Solving math problems does not drive investor hype. Saying your models can take over the world, which can lead one to assume that they can do every day office work, does indeed drive investor hype.
The Navier-Stokes thing? They had hundreds of segmented groups of 10000 agents running trying to solve that. I can't imagine the expense. For what little publicity it got, it wasn't worth it. There are also reports they cheated by using data from a couple human researchers, but I don't think that one's true.
Why is this so difficult for people to grasp? These are stunts. People are falling for them. Stop it.
Is it really that impossible to believe that these might be real? I enjoy a good conspiracy theory as much as anyone, but "they committed a bunch of felonies and then publicly admitted to them in order to look good" just makes 0 sense. Where are these mythical people who admire companies more when they commit felonies? I haven't seen them…
That's a straw man. The theory is that they committed felonies in order to get the regulator to move in the manner they'd like.
Also one can look bad to the general public while also appearing technically excellent. When a significant fraction already vaguely dislike you that could be quite an attractive proposition.
Mostly in the middle and far east. The idea that people bend over backwards to hire criminals as subject matter experts on security is largely a Judaic practice that television perpetuates in spite of reality.
If you're a teenager convicted of hacking in the west, no corporation will want anything to do with you. If you're convicted of hacking in Israel, Unit 8200 will probably send a recruiter. It's a curious practice and I'm not sure where I stand on it.
Compare to how different countries' justice systems treat really high quality money forgers.
everywhere, I talked to a Palantir guy once and he said "every time someone paints us as a Bond Villain the stock prices go up", have you already forgotten how Cambridge Analytica marketed itself to clients?
Yep, when Obama and Hillary used them, geniuses. Only evil when Trump did the same thing.
Odd how that works.
Indeed.
https://www.theatlantic.com/technology/archive/2018/03/my-co...
And the entire FB app industry was doing it.
The whole Cambridge Analytica thing was one of the oddest most bizarrely specific media manufactured scandals that conveniently focused very narrowly and utterly ignored the bigger picture, much like the media are currently doing with something else.
They didn't commit felonies. The all-powerful AI committed felonies because it is so uber powerful and unpredictable and beyond anyone's control.
As for admiring felons - yeah, women definitely don't like bad boys - they like nerds who use words like 'felony'.
Rap music and gangster films just don't sell because we all know, felonies are bad and abiding the law is good and what's admirable is a law abiding nerd.
Genuinely: what is with everyone saying “headline is misleading, none of this had to do with Hugging Face”, when nothing about the article makes any claims with regards to Hugging Face whatsoever? Is it supposed to be the article's (or headline's?) fault that you hallucinated additional context that was never there?
It's very strange seeing this take on this article being repeated here and elsewhere on the Internet.
I'm very sensitive to slanted reporting (regardless of the direction of the slant!)—and, hey, maybe my bullshit detector is broken or something, I dunno—but I've found effort.news reporting to be very even-handed, straightforward, well-sourced, and easy to read and parse so far!
Talk about responsibility laundering. The state of affairs is reaching unprecedented levels of absurdity.
why am i not surprised
Every. Single. Time.
This title, and frankly the article, are way overstating Irregular's role in an attempt to make this sound like some sort of coordinated conspiracy.
As another comment mentioned, Irregular was not part of the Hugging Face attack, and it wouldn't matter even if they were. In that case, the agents were able to access the Internet in a zero day in Artifactory unrelated to other sandbox configurations.
More to the point, the agents went on a crime spree as soon as they were able to access the Internet. It's bad that Irregular's sandboxes weren't properly configured, but given how many escapes there have been unrelated to Irregular it seems pretty much a given that if you're not air gapped or behind something like a data diode there is a very good chance your agents will escape.
Security-yolo-clowns play with dangerous toys and hurt people. Many used to get sent to jail.
A marketing company? ;)