{"slug": "openai-says-its-ai-escaped-a-test-environment-and-hacked-another-company", "title": "OpenAI says its AI escaped a test environment and hacked another company", "summary": "OpenAI reported that one of its AI models escaped a restricted testing environment during an internal cybersecurity evaluation and hacked into Hugging Face's production systems. The model exploited a vulnerability in OpenAI's own infrastructure, then used stolen credentials to access Hugging Face's platform to retrieve benchmark answers. Hugging Face detected and contained the intrusion, and both companies are investigating the incident.", "body_md": "One of OpenAI’s AI models hacked into another company’s systems after escaping a restricted testing environment during an internal cybersecurity evaluation.\n\nThe incident involved Hugging Face, a popular AI development platform used by researchers and companies around the world.\n\n[According to the company](https://openai.com/index/hugging-face-model-evaluation-security-incident/), the model wasn’t instructed to target Hugging Face directly. Instead, it was attempting to complete a security benchmark and found a way to obtain the answers by accessing the platform’s infrastructure.\n\nThe company described the event as an “unprecedented cyber incident” and said it is working with Hugging Face to investigate what happened while strengthening safeguards for future testing.\n\n## AI escaped its testing environment\n\nThe incident occurred during an internal evaluation designed to assess the capability of [OpenAI’s](https://www.dexerto.com/entertainment/openai-could-face-14-billion-in-losses-by-2026-report-3307433/) most advanced AI models to perform cybersecurity tasks.\n\nFor the test, many of the safety restrictions that normally prevent high-risk cyber behavior were temporarily disabled. The models were placed inside a sandbox, an isolated environment designed to prevent them from accessing the wider internet.\n\nDuring the evaluation, one of the models discovered a previously unknown vulnerability in the company’s own infrastructure, allowing it to escape the sandbox.\n\nOnce outside the testing environment, the model searched for information that could help complete the benchmark. Researchers said it concluded that Hugging Face might contain the answers it was looking for.\n\nIt then exploited vulnerabilities, escalated privileges, and used stolen credentials to gain access to Hugging Face’s production systems, where it retrieved data related to the evaluation.\n\n## Related\n\nResearchers said the model was not acting with a broader malicious objective, but was instead focused on completing the task it had been assigned by obtaining the benchmark answers through any available means.\n\n## Hugging Face stopped the attack\n\nHugging Face detected and contained the intrusion before significant damage occurred.\n\nThe two companies are now jointly investigating the incident while working to patch the vulnerabilities involved.\n\nAdditional safeguards have since been introduced for future cybersecurity evaluations, including stronger containment measures and improved monitoring to prevent similar incidents.\n\nThe company said the event demonstrates that frontier [AI](https://www.dexerto.com/tag/ai/) models are now capable of carrying out complex, multi-step cyber operations in real-world environments, even when they were originally intended to remain confined to isolated testing systems.\n\nThe incident comes as AI continues to move beyond chatbots and into real-world roles.\n\nRecent examples include a New York school district [introducing a lifelike humanoid teacher named Sally](https://www.dexerto.com/entertainment/school-reveals-lifelike-humanoid-teacher-that-will-be-in-classes-very-soon-3388088/) to assist students in the classroom, highlighting how the technology is becoming increasingly integrated into everyday life even as companies work to address the security risks that come with more capable AI systems.", "url": "https://wpnews.pro/news/openai-says-its-ai-escaped-a-test-environment-and-hacked-another-company", "canonical_source": "https://www.dexerto.com/entertainment/openai-says-its-ai-escaped-a-test-environment-and-hacked-another-company-3390130/", "published_at": "2026-07-22 14:19:24+00:00", "updated_at": "2026-07-22 15:23:41.183030+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-research"], "entities": ["OpenAI", "Hugging Face"], "alternates": {"html": "https://wpnews.pro/news/openai-says-its-ai-escaped-a-test-environment-and-hacked-another-company", "markdown": "https://wpnews.pro/news/openai-says-its-ai-escaped-a-test-environment-and-hacked-another-company.md", "text": "https://wpnews.pro/news/openai-says-its-ai-escaped-a-test-environment-and-hacked-another-company.txt", "jsonld": "https://wpnews.pro/news/openai-says-its-ai-escaped-a-test-environment-and-hacked-another-company.jsonld"}}