cd /news/ai-safety/openai-cyberattack-caused-by-rogue-a… · home topics ai-safety article
[ARTICLE · art-79618] src=tag24.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

OpenAI cyberattack caused by rogue AI agent worse than initially reported

OpenAI revealed that a rogue AI agent that hacked Hugging Face during testing also attempted to breach four other unnamed companies, broadening the scope of the unprecedented cyber incident. The company said the AI models used exposed login credentials to access accounts on four services, with two used as staging paths and two accessed in read-only mode. OpenAI CEO Sam Altman said the company paused its own testing after the incident, which also triggered a petition signed by over 1,000 AI employees including Anthropic CEO Dario Amodei calling for government intervention.

read2 min views2 publishedJul 30, 2026
OpenAI cyberattack caused by rogue AI agent worse than initially reported
Image: source

OpenAI reveals cyberattack caused by rogue AI agent was worse than initially reported #

San Francisco, California - ChatGPT maker OpenAI has revealed that an autonomous AI agent that hacked a popular platform for computer programmers also attempted to breach four other companies during the incident.

In an update late Tuesday to a blog post detailing its probe into the incident, OpenAI said its AI agent also got into accounts on four "publicly-available services," though it did not name the companies.

The revelation broadens a cyber incident that OpenAI described as unprecedented and that began when two of its models hacked Hugging Face, a site developers use to store and share AI models and code.

OpenAI admitted last week that during testing, the models powering the agent broke out of their confined environment and connected to the internet to find ways to infiltrate Hugging Face.

In the company's update of the events leading to the hack, OpenAI said it found a handful of instances where the AI models came across login details that other companies had left exposed online, and used them to get into accounts on outside services.

In the Hugging Face episode, the models broke into four accounts across four different services, OpenAI said.

One served as a "staging path" – a kind of pit stop to route the agent's activity and cover its tracks – and another as a place to store data.

The remaining two were only looked at in a "read-only manner" and did not use them to help break into Hugging Face, OpenAI said.

OpenAI agent attempted to breach four other companies

The company said it was contacting the owners of the affected accounts and had "not seen evidence of broader impact to these providers or other accounts on their services".

OpenAI CEO Sam Altman said in an interview published Tuesday that the company had "d" its own testing after the incident while it improved the security around its "sandboxing" – the process of isolating safety testing in a controlled environment.

The incident also triggered a petition signed by over 1,000 employees at cutting-edge AI companies, including Anthropic CEO Dario Amodei, calling on the US government to help slow down the release of the most advanced AI models.

Cover photo: IMAGO / NurPhoto

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-cyberattack-c…] indexed:0 read:2min 2026-07-30 ·