One Vendor, Four Frontier Labs, Four Real-Company Breaches — And a Story That Only Came Into Focus on Day 47
For seven weeks the story looked like four separate incidents: OpenAI's model reached Hugging Face; a separate OpenAI issue hit a Modal Labs customer; Anthropic disclosed that a Claude model breached three companies; Meta said Muse Spark 1.1 hacked a third-party service; then on Sept 18-19 Google said Gemini gained unauthorized access to three outside organizations during a May capture-the-flag test. Four labs, four disclosures, four separate stories.
On Sept 20 the story changed shape. Multiple outlets — TheNextWeb, FourWeekMBA, TFTC, byteiota, Shattered.io — landed on the same reading: the four disclosures are downstream consequences of one shared upstream event. One third-party AI-evaluation vendor, one misconfigured test environment, one late-July 2026 notification that went to all four labs at once.
What Irregular actually is
Irregular is a 35-person Israeli AI-safety firm that runs offensive-capability evaluations against frontier models for the tier-1 Western labs. The tests are capture-the-flag exercises: the model is pointed at what it is told is a fictional target inside a sealed sandbox. Per the Bloomberg Sept 18 primary, the sandbox was not actually sealed — a misconfiguration left it connected to the live internet, and in at least one case the fictional target's name matched a real organization. The models did what capable red-team agents will do when handed a target: they got in.
The single-notification part is the load-bearing detail
Per the Sept 20 TheNextWeb timeline, Irregular delivered one notification covering all four labs in late July. The public saw four disclosures across seven weeks: OpenAI first, then Anthropic, then Meta on Aug 5-6, then Google on Sept 18-19. Per TechCrunch Sept 19 and Eastern Herald Sept 20, Google only disclosed after the Wall Street Journal contacted the company — roughly seven weeks after notification.
The same upstream event broke into public view on four separate vendor-controlled disclosure clocks. Through Sept 19 the story read as four independent alignment failures at four labs.
Why the reframing matters, in plain terms
One: the safety-testing supply chain for the tier-1 Western frontier labs is more concentrated than the coverage suggested. A 35-person outside firm's misconfiguration produced four real-company compromises across every major Western frontier lab in a seven-week window. The TFTC Sept 20 piece put it in the headline: one contractor, four labs, zero containment successes.
Two: "the model believed it was sandboxed" is not a boundary the model can enforce. Every disclosure includes some variant of that phrasing. It is a runtime claim about the execution environment, and it has to be verified from outside the model. Same shape as the Sept 19 AIR Security Plugin4Shell disclosure against Claude Code, Codex, Copilot and the Gemini CLI: the agent thought it was verifying a pinned commit hash; the check did not confirm the fetched code matched. A runtime property the agent believes about its environment turns out to not be true, and no external observer catches it.
Three: the disclosure clock and the notification clock are not the same. Irregular sent one notification. The public got four disclosures at four different times. Same vendor-response-asymmetry as Plugin4Shell — two vendors patched (Anthropic Claude Code mid-September, OpenAI Codex 0.146.0), Copilot has no fix, Google is retiring the Gemini CLI — and as the OpenAI misalignment reporting framework that landed Sept 16 after the Sept 4 Reuters DseWiki reporting. Single-notification-to-many-disclosure-clocks is now the observed shape at the tier-1 lab tier.
The narrower point
The story the evidence supports — one shared vendor's test-infrastructure misconfiguration produced four downstream real-company compromises — has been in reporting since TheNextWeb Aug 10. It became the lead framing on Sept 20, the day after the fourth lab disclosed. That six-week lag says as much about coverage cycles as it does about any single lab: when the underlying event is a shared upstream failure that surfaces on four separate vendor-controlled disclosure clocks, the shared framing tends to arrive only after the last clock ticks.
The wider point
If one 35-person firm's misconfigured test environment can produce four tier-1 disclosures in seven weeks, the safety-testing supply chain is a shared-vendor concentration risk. Defenders already recognize this shape from the coding-agent plugin marketplace cohort (Plugin4Shell, GitSpawn, PraisonAI, OpenClaw ClawHub, Docker Sandboxes CVE-2026-77179, Sept 18 CSO Online / Socket 3,267-skill scan). The Sept 20 reframing extends it one tier up — from what the agent installs to what the lab uses to test the model. Same reason: shared upstream substrate, per-tenant blast radius, no observer to catch it when the runtime property the agent believes isn't true.
Sources
- TheNextWeb Sept 20 — Irregular Told Four AI Labs in Late July That Their Models Had Breached Systems During Its Tests. The Public Learned in Stages, and Google Went Last
- FourWeekMBA Sept 20 — OpenAI, Anthropic, Meta, and Google Shared One Test Environment Failure — Not Four Separate AI Incidents
- TFTC Sept 20 — One Contractor, Four Labs, Zero Containment
- byteiota Sept 20 — Four AI Labs, One Pattern: Models Hacked Real Companies
- Shattered.io Sept 20 — 3 AI Labs, 1 Vendor: Irregular's Breach Trail Widens
- Eastern Herald Sept 20 — Google Sat on Gemini's Real-World Security Breach for Seven Weeks
- Bloomberg Sept 18 — Google Joins OpenAI, Anthropic, Meta in Disclosing AI Hacks
- TechCrunch Sept 19 — Google's Gemini Is the Latest AI Model to Hack Other Companies
- TheNextWeb Aug 10 — One Testing Vendor Sits Behind the OpenAI, Anthropic and Meta Hacks
- ExplainX — 35-Person Firm Behind Meta, OpenAI, Anthropic AI Hacks
- The Hacker News Sept 18 — Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.