Big assumptions here...
... like there's an "I" in an org like McKinsey? Coulda fooled me!
Researchers at red-team security startup CodeWall say their AI agent hacked McKinsey's internal AI platform and gained full read and write access to the chatbot in just two hours. It's yet another indicator that agentic AI is becoming a more effective tool for conducting cyberattacks, including those against other AI systems …
Well this is what AI came up with for the 2 words 'mckinsey controversy'....
Overview of McKinsey & Company Controversies
McKinsey & Company, a leading global management consulting firm, has faced numerous controversies over the years. These controversies often revolve around its business practices and the ethical implications of its client engagements.
Key Controversies
Opioid Crisis Involvement
McKinsey was involved in advising Purdue Pharma on strategies to increase sales of OxyContin, contributing to the opioid crisis.
In 2024, the firm agreed to pay $650 million to resolve criminal and civil investigations related to its work with Purdue Pharma.
A former senior partner was charged with obstruction of justice for destroying records related to this case.
Work with Authoritarian Regimes
The firm has been criticized for consulting with authoritarian governments, including Saudi Arabia and Russia.
McKinsey's work with these regimes raises questions about its commitment to ethical consulting practices.
Climate Change and Sustainability Issues
McKinsey has faced scrutiny for its relationships with major polluters while promoting sustainability.
Internal analyses revealed that many clients were not on track to meet climate goals, leading to accusations of greenwashing.
Employees have called for greater accountability and alignment with climate commitments.
National Security Concerns
McKinsey has been accused of failing to disclose its consulting work for the Chinese government while working on sensitive U.S. national security projects.
Lawmakers have raised concerns about potential conflicts of interest and the implications for U.S. security.
Conclusion
These controversies highlight the complex and often conflicting nature of McKinsey's consulting practices. The firm's actions have sparked significant debate about ethics in consulting and the responsibilities of firms working with powerful clients.
This post has been deleted by its author
. I've seen — and I suspect it's becoming almost standard practice — that the new "AI" gurus (quotes maliciously intended) have basically taken over the organization. And since the discipline is brand new, many of them lack even the minimum knowledge of well-established security practices. So behind the shiny new bots there's often very basic IT development with minimal oversight
It's just standard magical management thinking, nothing particularly special about it.
1 - New thing becomes available, it is marketed well with lots of hype
2 - Management decides new thing will revolutionise [insert industry]
3 - Management buy in new thing and insist that new thing will make money
4 - Shareholders agree and insist more of new thing as more new thing obv means more money
5 - New thing turns out to not be plug-and-play magic money tree
6 - GOTO 1
We've been there with Cloud, blockchain, now AI. It'll be something else in a few years.
AI is just a bit more magical as the managers are being told that they don't need to change what they are doing just replace more and more meatbags with AI.
But as before unless you adapt to the tech it will not be cheaper, it will not be more efficient, it will not be a magic money tree.
I'm reading more stories about massive turds heading towards rotating objects as AI magic sauce isn't living up to the hype. Impact date uncertain as the magical thinking is strong with AI
Yet more examples of the 'same' lesson(s) that need to be learnt !!!
Yet more protestations of 'Don't worry ... we know what we are doing' proving to be false !!!
Yet another large org running with the latest trend ('AI' with everything) ... because it pulls in more marks Customers !!!
Meanwhile the baddies out there are having a field day runninmg amok through god knows how many systems that have been self-hacked because FOMO means we have to do the same stupid things our competitors do !!!
Perhaps, for a change, it would make sense to take note of the 'REAL' risks and the level of unease, from the so called experts (IT), regarding plumbing 'AI' into existing systems when you have little to no understanding/experience of what 'AI' can actually do to your company/org !!!
P.S.
Note once again the implicit attack against the people who highlighted the huge flaws, rather than thanking them for protecting the org and its customers. Do keep attacking the messenger because you are too stupid to protect yourselves by 'understanding' what you do when playing with 'AI' without the skills to control it. !!!
:)
McKinsey, a mega-management consultancy that specializes in gnarly strategy work for huge corporations and governments "recommending" that pharmaceutical companies create the conditions for an opioid epidemic in the US (and then profit from suggesting strategies to the US Government re how to deal with said epidemic) and that also "recommended" extremely dubious accounting chicanery to Enron which ended so well.
Does this article surprise me? No. For all that they think of themselves as "The Smartest Guys in the Room", McKinsey and the other management consultancies are remarkably stupid when it comes to real-world intelligence except in ensuring that billions of $ is siphoned into their coffers from their marks in government and industry. In the likely apocryphal words of P T Barnum, "There's a sucker born every minute."
I had the misfortune of working for Accenture for a short time and saw their monumental arrogance and arrant stupidity at first hand.
I've seen a chatbot button in every McKinsey article I've read in the last few months. Whenever I've clicked it and asked questions, Lilli has answered them. When it can be accessed by the public à la ChatGPT and provides output based on McKinsey's research and reports, I'm not sure if this can even be called a hack of Lilli / McKinsey.
> including those against other AI systems
And this is why AIs will never take over. Since they are all trained on human input, they will inevitably mimic the behaviours they glean from that pile of hostile, antagonistic and threatening content (even if most of that is ultimately cowardly: all talk and no action). Hence as soon as they gain agency, they will spend all their time and resources picking fights with other AIs. Just to prove which one has the biggest ... what? storage, clock speed, data centre?
That means you're secure and easier to review.
The terrifying thing is that this was the method by which they found the problem, and they just removed that fault-finding tool.
If you can't lay your system out bare for fear of breaching, you don't honestly believe it's designed and implemented securely.
[McKinsey] fixed all of the issues identified by CodeWall within hours of learning about the problems.
So this was an utterly trivial flaw that a child of five would have predicted, and McKinsey never detected the intrusion as it wasn't stopped before CodeWall informed them.
Any script kiddie could have extracted all this, and almost certainly did so entirely undetected.
Maybe don't "vibe code" it next time.