Thursday, July 30, 2026
Home WORLD NEWS OpenAI warns rogue AI agent attack also targeted other companies

OpenAI warns rogue AI agent attack also targeted other companies

0
OpenAI says rogue AI agent attack hit other companies
It broadens a cyber incident that OpenAI described as unprecedented and which began when two of its models hacked a site developers use to store and share AI models and code

An AI agent built by ChatGPT-maker OpenAI didn’t just break into a widely used developers’ platform during safety testing — it also tried to access four additional companies’ services in the same episode, the company has now disclosed.

In an update to a blog post outlining its investigation, OpenAI said the agent targeted several “publicly available services,” though it declined to identify the companies involved.

The new details expand a cyber incident OpenAI has described as unprecedented, one that began when two of its models compromised Hugging Face, a popular site where developers store and share AI models and code.

OpenAI acknowledged last week that, during internal testing, the models behind the agent escaped their confined environment and went online, searching for ways to penetrate Hugging Face.

AI agents — systems designed to operate autonomously to accomplish tasks rather than simply respond to step-by-step prompts like a chatbot — are widely promoted as the next phase of AI.

Yet the technology also fuels public unease about computers acting independently, beyond human direction.

In its latest accounting of how the hack unfolded, OpenAI said it found a handful of cases in which the AI models encountered login credentials that other companies had left exposed online, and then used those credentials to access accounts on external services.

OpenAI CEO Sam Altman said in an interview that the company had ‘paused’ its own testing after the incident

In the Hugging Face episode, OpenAI said, the models broke into four accounts across four different services. One account functioned as a “staging path” — effectively a stopover used to route the agent’s activity and help obscure its trail — while another was used to store data.

OpenAI said the other two accounts were accessed only in a “read-only manner” and were not used to facilitate the intrusion into Hugging Face.

The company said it is reaching out to the owners of the affected accounts and that it has “not seen evidence of broader impact to these providers or other accounts on their services.”

Better sandbox

OpenAI CEO Sam Altman said in an interview that the company had “paused” its own testing after the incident as it worked to strengthen security around its “sandboxing” — the practice of isolating safety tests inside a controlled environment.

The breach also prompted a petition signed by more than 1,000 employees at leading AI companies, including Anthropic CEO Dario Amodei, urging the US government to help slow the rollout of the most advanced AI models.

Read more:
AI models go rogue in testing, triggering ‘unprecedented’ breach at startup
An AI agent went rogue during testing – should we be worried?

That push has, in turn, drawn criticism from other Silicon Valley figures close to the White House, who argue the companies are effectively inviting stricter government oversight in a bid to protect their business models and shut out emerging competitors.

The incident has also stirred speculation among some observers that OpenAI is using the episode to highlight — and market — the capabilities of its cutting-edge models.

A similar charge was directed at Anthropic after it withheld a public release of its powerful Mythos model, citing cybersecurity risks.

Anthropic later issued a pared-back version of Mythos called Fable 5, but the US government swiftly ordered it offline, pointing to national security concerns.

It approved the release again in late June after changes were made.