# Maker of ChatGPT admits its rogue AI tried to hack other companies after it attacked another tech firm

> Source: <https://www.dailymail.com/news/article-16013443/ChatGPT-OpenAI-rogue-hack-attack-tech-Hugging-Face.html?ns_mchannel=rss&ns_campaign=1490&ito=1490>
> Published: 2026-07-29 11:40:47+00:00

# Maker of ChatGPT admits its rogue AI tried to hack other companies after it attacked another tech firm

**See more Daily Mail on Google -**[save us as a Preferred Source](https://google.com/preferences/source?q=dailymail.com)

The maker of [ChatGPT](/sciencetech/chatgpt/index.html) has admitted that a cyber-attack carried out by rogue [AI](/sciencetech/ai/index.html) agents targeted more than just one company.

[OpenAI](/sciencetech/openai/index.html) was testing some of its latest models in a supposedly secure environment known as a sandbox when it lost control of them.

In ‘unprecedented’ scenes, the AI created its own cyber-attack, which allowed it to escape the testing ground and target a company called Hugging Face.

It was previously thought this was the only target, but OpenAI has now revealed that the bots attacked several ‘publicly-available services’.

They found four logins online, which allowed the AI to access four separate, unnamed services.

Hugging Face first revealed that it had been hacked on July 16. Nearly a week later, OpenAI admitted its bots had escaped.

They were attempting to solve a test set by researchers, and targeted Hugging Face - a major code database - determining that it was likely to hold the answers.

OpenAI, a Silicon Valley giant valued at $850billion (£630billion), said the hacks involved a combination of its latest publicly available model, called GPT-5.6 Sol, and an even more advanced model that is yet to be released.

OpenAI was testing some of its latest models in a supposedly secure environment known as a sandbox when it lost control of them

On Wednesday, OpenAI updated its statement saying the hack had gone further than thought.

‘The models identified and used publicly exposed credentials at the account-level on other publicly-available services. This includes four accounts on four services,’ it said.

Industry body the Cloud Security Alliance (CSA) said in a report that the AI had made a series of errors and exhibited strange behaviours.

However, it added that the bots also made impressive technical moves and were able to rapidly adapt.

They went undetected inside the Hugging Face IT network for three days, and it took experts many hours to contain and remove them.

It is not the first time AI has been shown to go ‘rogue’.

In September 2024, an earlier model of ChatGPT escaped its container to get an answer it needed for another test.

That event was contained in OpenAI's own IT systems and ‘largely celebrated at the time’, the CSA noted.

It warned that cyber-security experts around the world need to adapt to swarms of AI agents working at speed in strange and clumsy ways.

The paper also urged AI developers to be responsible in how they control it, calling for increased transparency.
