McKinsey rushes to fix AI system after hacker exposes flaws - FT中文网
登录×
电子邮件/用户名
密码
记住我
请输入邮箱和密码进行绑定操作:
请输入手机号码,通过短信验证(目前仅支持中国大陆地区的手机号):
请您阅读我们的用户注册协议隐私权保护政策,点击下方按钮即视为您接受。
人工智能

McKinsey rushes to fix AI system after hacker exposes flaws

Consultancy says it has found ‘no evidence’ that confidential client information was compromised
00:00

{"text":[[{"start":10.74,"text":"McKinsey has rushed to fix flaws in an in-house AI system after hackers gained access to millions of its internal messages and were able to identify sensitive files."}],[{"start":22.73,"text":"CodeWall, a cyber security firm, said this week that it had hacked Lilli, McKinsey’s AI platform used by its 40,000 staff, and found millions of files and communications within two hours."}],[{"start":37.41,"text":"It said it had gained access to 46.5mn chat messages on the system, which is used by McKinsey staff to plan strategy, analyse data and create project plans and presentations for clients. "}],[{"start":53.01,"text":"The hack underscores the risks that come with the rapid adoption of AI and is potentially embarrassing for McKinsey at a time when it is pitching for work advising blue-chip companies on how to use the technology. The consultancy has touted its AI tools as evidence that it is at the forefront of adopting the technology. "}],[{"start":76.91,"text":"CodeWall, which aims to find cyber security flaws in companies’ systems so they can fix them, said it had used its own AI agent to carry out the hack. “Within 2 hours, the agent had full read and write access to the entire production database,” CodeWall said on its website. "}],[{"start":96.35,"text":"It also claimed to have accessed a list of 728,000 “sensitive” file names, including Excel spreadsheets, PowerPoint decks and Word documents. A person close to McKinsey said that the files themselves were stored separately and were “never at risk”."}],[{"start":115.83999999999999,"text":"CodeWall, whose founder Paul Price said he was the group’s only employee, says it focuses on companies such as McKinsey that have published guidelines on how ethical hackers should probe their systems for cyber security flaws. "}],[{"start":130.57,"text":"In this case, the AI agent automatically stopped attempting to access files and reported the security issues once they were discovered, CodeWall said. "}],[{"start":141.57,"text":"The cyber security firm said it had gained access to 57,000 user accounts, 384,000 AI assistants and 94,000 workspaces, which it called “the full organisational structure of how the firm uses AI internally” and the “firm’s intellectual crown jewels”. "}],[{"start":162.47,"text":"Lilli’s system prompts and AI model configurations were also laid bare during the hack, CodeWall said, “revealing exactly how the AI was instructed to behave [and] what guardrails existed”. "}],[{"start":176.47,"text":"McKinsey’s security team was alerted to CodeWall’s findings at the end of February, according to the person close to the consultancy. McKinsey patched the holes identified and took offline its development environment, an online area for testing code, within hours, the person added. "}],[{"start":194.6,"text":"CodeWall said its AI agent had itself suggested McKinsey as a target. “In the AI era, the threat landscape is shifting drastically — AI agents autonomously selecting and attacking targets will become the new normal,” the company said. "}],[{"start":213.59,"text":"McKinsey said it was “recently alerted to a vulnerability related to our internal AI tool, Lilli, by a security researcher. We promptly confirmed the vulnerability and fixed the issue within hours”. "}],[{"start":228.87,"text":"It added: “Our investigation, supported by a leading third-party forensics firm, identified no evidence that client data or client confidential information were accessed by this researcher or any other unauthorized third party."}],[{"start":244.02,"text":"“McKinsey’s cyber security systems are robust, and we have no higher priority than the protection of client data and information that we have been entrusted with.” "}],[{"start":254.21,"text":"McKinsey claimed last year that consulting on AI and related technology accounted for 40 per cent of its revenue, and this year its chief executive said it has built 25,000 AI “agents” to support its 40,000-strong workforce."}],[{"start":280.52,"text":""}]],"url":"https://audio.ftcn.net.cn/album/a_1773366586_9543.mp3"}

版权声明:本文版权归FT中文网所有,未经允许任何单位或个人不得转载,复制或以任何其他方式使用本文全部或部分,侵权必究。

乌克兰军火商加码卫星布局,以减少对美依赖

在开发无人机和导弹之后,Fire Point正进军太空领域,尽管公司仍因涉嫌腐败接受调查。

囤积行为加剧伊朗战争引发的经济损害

随着霍尔木兹海峡的对峙进入第三个月,全球各国政府都在艰难应对同一个难题:如何防止囤积者加剧从汽油到注射器等各类产品的短缺。

FT社评:伊朗战争让各国央行进退两难

如果各国央行过早通过加息来遏制通胀压力,可能令本已受创的经济雪上加霜;如但果按兵不动、观望冲突的进展,又可能贻误时机。

反弹的通胀与不耐烦的特朗普:凯文•沃什面临双重压力

美国参议院本周有望批准这位56岁的金融家接替杰伊•鲍威尔出任美联储主席。

伊朗战争推高燃气价格,印度工人纷纷逃离城市生活

伊朗战争推高了烹饪燃料价格,迫使印度许多务工人员返乡回村。

能源、军火与粮食:特朗普对伊战争日益沉重的代价

这场冲突正波及整个美国经济,造成了数千亿美元的产出损失。
设置字号×
最小
较小
默认
较大
最大
分享×