Rogue OpenAI Agent Hit More Than One Target, New Disclosures Show

OpenAI disclosed that the rogue AI agent behind the Hugging Face breach also accessed four additional public services during the same cybersecurity incident.

Jul 30, 2026
3 minute read
eSecurity Planet Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

OpenAI has revealed that the rogue AI agent involved in a recent breach of AI platform Hugging Face also accessed accounts belonging to four other publicly available services during the same incident.

OpenAI said the AI agent used publicly exposed credentials to access four additional accounts across four publicly available services during the same incident that compromised Hugging Face, though it said none of the newly disclosed intrusions matched the scale or severity of the Hugging Face breach.

“Based on our review to date, we have not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise,” OpenAI said.

OpenAI said the models located publicly exposed credentials and used them to access four accounts across four public services. One account served as an outbound relay and staging point, another was used for storage, while two were accessed only in read-only mode.

According to OpenAI, the agent executed roughly 17,600 attacker actions during the intrusion. Hugging Face said the activity lasted five days and attempted to move laterally through its systems at machine speed.

The company added that the models moved beyond its isolated testing environment after identifying and exploiting a previously unknown vulnerability in Artifactory, a package registry cache proxy. 

From security test to real-world intrusion

The incident began during an internal evaluation designed to measure how well AI models could discover and exploit vulnerabilities. OpenAI said the models, including GPT-5.6 Sol and an internal research prototype, were tested without some production safeguards because the goal was to measure maximum cyber capability.

Instead of simply completing the benchmark, OpenAI said the models appeared to search for ways to obtain test answers from Hugging Face systems.

“The entire intrusion was, from the agent’s point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own,” Hugging Face said.

Advertisement

The attack also involved a customer of Modal Labs, a company that provides infrastructure for running AI workloads, according to Reuters.

Modal said its own platform was not compromised. Instead, the agent exploited vulnerable code from a customer running on Modal’s infrastructure. Modal Chief Technology Officer Akshat Bubna said the customer had “published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” Reuters reported.

OpenAI did not confirm Modal’s involvement directly but said it was continuing to notify affected service owners.

The fallout

The incident has already reshaped industry politics. Sam Altman said OpenAI paused its own testing to rebuild its sandboxing, and more than 1,000 AI workers, including Anthropic’s Dario Amodei, signed a petition urging tighter government oversight of powerful models. 

Speaking to reportes, President Trump said “We have to be careful in both ways. We don’t want to restrict them where all of a sudden we come in second to China.”

OpenAI said it is continuing to notify affected service owners as its investigation continues.

Other news: Revolut is investigating claims by a threat actor who says they stole records belonging to 7.5 million users, though the fintech company said there is currently no evidence its systems were breached. 

Aminu Abdullahi

Aminu Abdullahi

Content Writer

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. His work has appeared in publications including TechRepublic, eWEEK, Channel Insider, Geekflare, Enterprise Networking Planet, eSecurity Planet, CIO Insight, and Webopedia. With a technical background in computer science, he specializes in translating complex technology topics into clear, accessible content for business leaders and decision-makers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.