OpenAI has revealed that the rogue AI agent involved in a recent breach of AI platform Hugging Face also accessed accounts belonging to four other publicly available services during the same incident.
OpenAI said the AI agent used publicly exposed credentials to access four additional accounts across four publicly available services during the same incident that compromised Hugging Face, though it said none of the newly disclosed intrusions matched the scale or severity of the Hugging Face breach.
“Based on our review to date, we have not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise,” OpenAI said.
OpenAI said the models located publicly exposed credentials and used them to access four accounts across four public services. One account served as an outbound relay and staging point, another was used for storage, while two were accessed only in read-only mode.
According to OpenAI, the agent executed roughly 17,600 attacker actions during the intrusion. Hugging Face said the activity lasted five days and attempted to move laterally through its systems at machine speed.
The company added that the models moved beyond its isolated testing environment after identifying and exploiting a previously unknown vulnerability in Artifactory, a package registry cache proxy.
From security test to real-world intrusion
The incident began during an internal evaluation designed to measure how well AI models could discover and exploit vulnerabilities. OpenAI said the models, including GPT-5.6 Sol and an internal research prototype, were tested without some production safeguards because the goal was to measure maximum cyber capability.
Instead of simply completing the benchmark, OpenAI said the models appeared to search for ways to obtain test answers from Hugging Face systems.
“The entire intrusion was, from the agent’s point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own,” Hugging Face said.
Modal customer also caught in the chain
The attack also involved a customer of Modal Labs, a company that provides infrastructure for running AI workloads, according to Reuters.
Modal said its own platform was not compromised. Instead, the agent exploited vulnerable code from a customer running on Modal’s infrastructure. Modal Chief Technology Officer Akshat Bubna said the customer had “published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” Reuters reported.
OpenAI did not confirm Modal’s involvement directly but said it was continuing to notify affected service owners.
The fallout
The incident has already reshaped industry politics. Sam Altman said OpenAI paused its own testing to rebuild its sandboxing, and more than 1,000 AI workers, including Anthropic’s Dario Amodei, signed a petition urging tighter government oversight of powerful models.
Speaking to reportes, President Trump said “We have to be careful in both ways. We don’t want to restrict them where all of a sudden we come in second to China.”
OpenAI said it is continuing to notify affected service owners as its investigation continues.
Other news: Revolut is investigating claims by a threat actor who says they stole records belonging to 7.5 million users, though the fintech company said there is currently no evidence its systems were breached.





