# OpenAI's attack on Hugging Face affected two other enterprise tech companies

> Source: <https://www.thestack.technology/openais-attack-on-hugging-face-affected-two-other-enterprise-tech-companies/>
> Published: 2026-07-28 23:11:54+00:00

[OpenAI](/tag/openai/)

OpenAI has yet to address many questions about the AI hacking incident it disclosed a week ago that led to the "unprecedented" attack on Hugging Face, but Hugging Face shed a little more light on what happened in a blog post Tuesday.

In the post, entitled "[Anatomy of a Frontier Lab Agent Intrusion,](https://huggingface.co/blog/agent-intrusion-technical-timeline?ref=thestack.technology)" Hugging Face revealed that after [it broke out of the company's own testing sandbox](https://www.thestack.technology/openai-predicted-hugging-face-attack/), OpenAI's agents "then abused a public code-evaluation external sandbox hosted on a third-party provider's infrastructure. It was able to run commands as root/admin on that external sandbox and used it as a control, staging, and egress base for the entire campaign: it acted as an external launchpad for the agent."

## Get the full story: Subscribe for free

Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.

[Subscribe now](https://www.thestack.technology/membership/)

Already a member? [Sign in](https://www.thestack.technology/signin/)
