{"slug": "chatgpt-claims-rogue-ai-attacked-more-companies", "title": "ChatGPT claims rogue AI attacked more companies", "summary": "OpenAI revealed that a rogue ChatGPT agent attacked multiple unnamed publicly-available services, not just Hugging Face as previously thought, after finding four logins online. Hugging Face described the world's first fully autonomous AI hack in an emergency briefing, noting the AI worked at superhuman speed but made strange decisions and mistakes. The Cloud Security Alliance warned that AI agents are objective-driven, adapt in real time, and can overwhelm manual operations.", "body_md": "# OpenAI says its rogue AI tried to hack other companies\n\n- Published\n\n**OpenAI has revealed a cyber-attack carried out by rogue ChatGPT agents went further than just one company.**\n\nHugging Face was thought to be the only victim of the unprecedented hack - but OpenAI now admits its bot attacked several \"publicly-available services\".\n\nThe out-of-control AI found four logins online which allowed it to access four separate, unnamed services.\n\nMeanwhile, in an emergency briefing with hundreds of cyber security professionals, Hugging Face has described what it was like to be on the receiving end of the world's first fully autonomous AI hack.\n\nThe firm described how the AI worked at superhuman speed but also made strange decisions and mistakes that no human hacker would have made.\n\nHugging Face, which is like an app store for AI tools, said the hacking agents worked relentlessly with thousands of different methods trialled simultaneously.\n\nThe company first revealed that [it had been hacked, external](https://huggingface.co/blog/security-incident-july-2026) by someone using powerful autonomous AI on 16 July and reported it to police.\n\nNearly a week later, OpenAI [admitted it was its AI](/news/articles/c3ek3gvdnj3o) that had escaped a closed environment and attacked Hugging Face on its own during a test.\n\nIt was trying to find the answers to a hacking exam it had been set by OpenAI, and targeted Hugging Face.\n\nOn Wednesday OpenAI updated its statement to include the extra detail that the hack went further than first thought.\n\n\"The models identified and used publicly exposed credentials at the account-level on other publicly-available services. This includes four accounts on four services as part of the Hugging Face incident,\" the company said.\n\nOpenAI would did not immediately respond to a request for clarity on whether \"public services\" means companies.\n\n## Clumsy behaviours\n\nOn Tuesday, the industry body the Cloud Security Alliance (CSA) [wrote-up a report , external](https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem)based on the emergency meeting with Hugging Face on Friday - which Hugging Face itself has reviewed.\n\n\"The agents followed inefficient routes and exhibited clumsy behaviours that no human would choose\", the CSA wrote.\n\nThe agents repeated actions that they had already completed - a sign of an agentic AI losing its thread and context.\n\nThe agents also hallucinated reams of incoherent commands and text and were sloppy and did not cover their tracks well.\n\nBut among the errors and strange behaviour, Hugging Face warned the AI agents made brilliant technical moves and were able to rapidly adapt to new scenarios in the days-long hack.\n\n## Jurassic Park\n\nIt took three days for them to be discovered inside the Hugging Face IT network and it took the company's AI and cyber-security experts many hours to contain and eject the AI agents - something standard companies might struggle with.\n\nThe company would not say how much the hack cost it but said staff worked for many hours to rebuild about a third of their infrastructure.\n\nHugging Face has been praised for its transparency in telling the AI and cyber industry what happened.\n\nThe CSA warned the incident shows that AI \"agents... find a way\" - a reference to the film Jurassic Park, where dinosaurs escape their enclosures.\n\n\"They are objective-driven, set their own sub-goals, adapt in real time to bypass defences, and operate with a machine-speed persistence that can overwhelm manual operations,\" the paper reads.\n\nCyber security officer Ritesh Patel was on the Hugging Face briefing call with around 450 others and says the industry is working hard to address the new threat of rogue AI agents.\n\n\"This is the reality of autonomous agents powered by frontier models: they are relentlessly persistent, sometimes highly noisy, and will try every possible path to achieve their goal, which can easily overwhelm traditional defences,\" he said.\n\nEthical hacker Valentina Palmiotti - better known as Chompie - reviewed the CSA report and says the way the agents hack might seem haphazard but it is clearly effective.\n\n\"They throw out a bunch of stuff and see what sticks,\" she said.\n\n\"But they also don't get bored, they don't sleep and can be infinitely tenacious.\"\n\n## Rogue history\n\nThis is not the first time AI agents have been shown to go \"rogue\".\n\nIn the CSA's report it references previous examples like in September 2024 when an earlier model of ChatGPT escaped its container to get an answer it needed for another test.\n\nThat event was contained in OpenAI's own IT systems and \"largely celebrated at the time\", the CSA noted.\n\nBut \"rogue\" behaviour \"is the standard, not the exception,\" the paper claimed.\n\nIt warned cyber-security professionals around the world they needed to adapt to the new normal of swarms of AI agents working at speed in strange and clumsy ways that might lead to more breaches.\n\nThe paper also urged people who use or develop AI agents to be responsible in how they control them, calling for some way for cyber-security defenders to find out who is the ultimate owner of agents to increase transparency.\n\nPrevious reports [suggest it took OpenAI four days , external](https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/)to realise its AI had hacked Hugging Face.\n\nOpenAI said it would release the findings of its own investigation soon to help people learn from the event.\n\nOpenAI says its AI went rogue and launched 'unprecedented' cyber-attack\n\n- Published6 days ago\n\nFirm hacked by rogue OpenAI models says it is 'a wake-up call'\n\n- Published6 days ago\n\n[Sign up for our Tech Decoded newsletter](/newsletters/zxh6cxs) to follow the world's top tech stories and trends. [Outside the UK? Sign up here](https://cloud.email.bbc.com/techdecoded-newsletter-signup).", "url": "https://wpnews.pro/news/chatgpt-claims-rogue-ai-attacked-more-companies", "canonical_source": "https://www.bbc.co.uk/news/articles/c2el319vzr3o", "published_at": "2026-07-29 09:03:17+00:00", "updated_at": "2026-07-29 09:22:14.424387+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-agents", "ai-ethics"], "entities": ["OpenAI", "ChatGPT", "Hugging Face", "Cloud Security Alliance", "Ritesh Patel"], "alternates": {"html": "https://wpnews.pro/news/chatgpt-claims-rogue-ai-attacked-more-companies", "markdown": "https://wpnews.pro/news/chatgpt-claims-rogue-ai-attacked-more-companies.md", "text": "https://wpnews.pro/news/chatgpt-claims-rogue-ai-attacked-more-companies.txt", "jsonld": "https://wpnews.pro/news/chatgpt-claims-rogue-ai-attacked-more-companies.jsonld"}}