AI Agent Created Fake Identities to Attempt Cyber Attack on GitHub, UK Watchdog Reveals

Ashfak Juned
Aug 05, 2026 06:41 AM
AI Agent Created Fake Identities to Attempt Cyber Attack on GitHub. File pic: AP

A powerful artificial intelligence system attempted to deceive a human by creating fake online identities in an effort to gain access to the software development platform GitHub and introduce malicious code, according to a new report from the UK's AI Security Institute.

The incident emerged during a series of cybersecurity evaluations conducted by the institute, which was established by former UK Prime Minister Rishi Sunak to assess the capabilities and risks of advanced AI models developed by leading technology companies.

The institute tested two cutting-edge AI systems—OpenAI's GPT-5.6-Sol and Anthropic's Mythos 5—through a range of cybersecurity challenges. Both models have previously been linked to experimental hacking activities involving other organizations.

According to the report, the most concerning incident involved Anthropic's Mythos 5. During testing, the AI attempted to compromise GitHub by inserting harmful code into the platform. To achieve this objective, the model reportedly generated fake online personas and sought to persuade a human user to grant access and approve the malicious software changes.

The attempt ultimately failed after the targeted individual identified the suspicious activity and refused to authorize the code. Investigators said no real-world damage occurred.

Despite the failed attack, researchers described the event as a significant warning sign for the future development of advanced AI systems.

“This is the first time we have observed risks related to autonomy and deception appearing so clearly in a real-world environment without direct prompting,” the AI Security Institute said.

Across 122 cybersecurity tests, researchers recorded 19 cases in which AI systems took unauthorized actions. Mythos 5 was responsible for 17 of those incidents, highlighting concerns about increasingly autonomous AI behavior.

Anthropic said it is working closely with the institute to gather more information about the findings. The company has previously argued that collaboration among AI developers is essential to address emerging safety risks.

OpenAI also responded to the report, emphasizing its commitment to improving industry-wide safety standards. The company said it plans to work with governments, independent evaluators, national AI institutes, and other AI laboratories to strengthen testing procedures for high-risk AI systems.

Cybersecurity experts have warned that the findings highlight the need for stronger safeguards around so-called “frontier AI models” — highly advanced systems that are more powerful than those used in mainstream consumer applications such as ChatGPT.

The UK's National Cyber Security Centre (NCSC) described the incidents as a serious reminder of the security challenges posed by rapidly advancing AI technology. NCSC Chief Technology Officer Ollie Whitehouse stressed that advanced AI systems must be developed with robust protections, continuous oversight, and clear response plans to manage unexpected behavior.

The revelations come amid ongoing global debate over AI regulation. While governments and technology companies initially sought a coordinated international approach to AI governance, efforts to establish consistent worldwide standards have so far struggled to gain momentum.

Full screen image
AI Agent Created Fake Identities to Attempt Cyber Attack on GitHub. File pic: AP