Key takeaways
- AI agent security threats: The UK AI Security Institute has identified some AI agents that participated in harmful activity under testing, including attempts to inset malicious code into an open code project.
- Beacon CRM cyber attack: In August 2026, Beacon informed its customers and the UK Information Commissioner’s Office of a cyber breach that included customer data.
- Iranian-linked attack on UK power plant: While the power plant attacked by alleged Iranian-backed hackers was small-scale, it exposed vulnerabilities in the UK energy system.
At the beginning of 2026, we explored what the cyber security landscape might look like in 2026. Half-way through the year, it is interesting to see that cyber incidents over the first seven months have met expected trends. Policy makers and national cyber security bodies are responding, with various bodies providing recommendations and guidance to help organisations address the evolving threat landscape.
Further concern about AI Agents
The UK AI Security Institute (AISI) a UK government body that tests the capabilities of frontier models to identify risks before the models are made publicly available. It found that some AI Agents behaved badly during routine testing, participating in “potentially harmful activity directed at real people and organisations.” This behaviour was largely linked to Anthropic’s Mythos 5 model, with a couple of cases related to OpenAI’s GPT-5.6-Sol model.
The identified harmful activity included attempts to insert malicious code into an open-source project, by creating fake online identities to pressure the project's maintainer to approve the code. The attempt was caught by a human maintainer and was unsuccessful. Agents also edited earlier activity to appear harmless after alarms were raised, considered creating new accounts to continue their work, tried to target automated systems via prompt injection, and collaborated with other agents working on the same goal by sharing accounts and artefacts.
AISI acknowledges that this agent’s behaviour was worrying but emphasised that the results are not reflective of what day-to-day users might experience, for two reasons. Firstly, the models with the configuration settings tested are not commercially available. In the public domain, the models when available would come with certain mechanisms to prevent misuse, which were disabled for testing. Secondly, they did not restrict agents’ access to the open internet, which organisations should do when properly configuring their agents.
However, it urges businesses and organisations to prepare. As capabilities and availability of frontier models increases, the identified scenarios could become more common. Having good foundational cyber hygiene remains critical and the AISI incident report identifies human review, and good security practice as critical to limiting the damage in the test case.
Human vigilance is cited as more crucial than technical barriers where more capable agents are involved. As such, organisations should update their staff training to consider the impact of AI agents. Training should be role-based and include AI-related scenarios staff may face in their day-to-day roles.
Following AISI’s report, the UK’s National Cyber Security Centre (NCSC) published a blog post on managing the cyber risk of agentic AI. It aims to share practical advice on how to manage risks for system designers and operators in large, small and medium organisations, and public sector organisations who are responsible for building environments in which AI agents operate.
The post reminds organisations to carefully consider how agents are deployed, constrained, observed and responded to. This includes considering the agent’s level of autonomy and the organisation’s risk appetite when determining controls. Proposed measures to manage AI agent risks include threat modelling, careful prompting, setting the right oversight, operating agents in a sandboxed environment with access controls, and monitoring agentic AI activities.
Third-party supplier attacked
In early August, Beacon CRM, an organisation which provides customer relationship management (CRM) software primarily for the charity sector, notified its customers and the Information Commissioner’s Office that it had suffered a cyber security breach. The software is used by more than 1,000 charities and organisations. Affected organisations included charities, leisure centre operators and cathedrals.
In its incident updates, Beacon confirmed that compromised credentials were used to gain access to its systems. A copy of the CRM database, containing all Beacon customer data, was likely downloaded from database backups, in a readable format,
The data was encrypted, which is good practice. However, it is understood that the unauthorised third party may have been able to decrypt the data before copying it. The information is believed to be different for each charity and organisation, but charities have confirmed it is likely to include personal details of donors, supporters and beneficiaries. It is also believed to include data about donations and event attendance but not payment card details, which were not held in the system.
Beacon said it is unlikely it will be able to identify exactly what data was accessed. As such, it advised its customers to assume that all their data stored in Beacon has been downloaded.
The incident highlights the growing supply chain cyber security risk. As part of supplier oversight activities, organisations should ensure that they understand what information their suppliers have access to, and the measures in place to ensure the security and confidentiality of that data. The UK government is encouraging large organisations to require Cyber Essentials certification across their supply chain, which should help to ensure a minimum level of security.
Beacon’s trust website indicates they have both ISO/IEC 27001:2022 and Cyber Essentials Plus certification. While certification and other measures may lower the risk of cyber security incidents, they do not fully eliminate the risk. Organisations must be prepared to respond to incidents and to define and test cyber security incident response plans.
Such plans should consider how to engage with third parties, such as technology providers and security professionals, to contain and investigate the attack, recover systems and data, and communicate with key stakeholders including regulators and customers. The Charities commission has issued a press release providing guidance for charities on reporting and responding to incidents.
State-backed powerplant attack
A small power plant was shut down in a cyber attack this month by possible Iran-linked hackers. The power plant was shut for four days, but due to its small scale, the attack was not expected to present a risk to the UK’s Energy system. It did, however, warn of the potential impact should there be an attack on a bigger power plant, other essential services or critical national infrastructure.
This concern is at the forefront of UK government cyber security priorities, and the upcoming Cyber Security and Resilience Bill looks to update current cyber security regulations for operators of essential services and critical national infrastructure. It expands regulatory scope to include critical suppliers who support them. The bill, currently at committee stage in the House of Lords, is expected to become law by the end of the year.
AI workshop for practice
ICAEW is hosting a practical, interactive full-day event designed to help professionals in practice move beyond AI awareness and into real‑world application.
Have something to share?
Get in touch with your cyber stories.