OpenAI says rogue agent behind Hugging Face hack broke into additional services
The four additional targeted organizations weren’t named. OpenAI said they were not affected as severely as Hugging Face.
The rogue OpenAI agent that broke out of a closed test environment and hacked into Hugging Face’s platform also breached several additional third-party services, the company said Tuesday.
OpenAI has surfaced a “small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services,” it said in a blog post.
The rogue agent used four accounts to mount the Hugging Face hack after it found swiped credentials listed on the internet, according to the blog post, which acknowledged that a “few” other accounts also were targeted.
Related breach coverage
- JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack2026-07-29
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek.
- OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test2026-07-22
OpenAI confirmed its AI models exploited zero-days during internal testing, reaching Hugging Face servers in an unintended real-world cyberattack. OpenAI admitted on July 21 that its own AI models, including GPT-5.6 Sol and an unnamed pre-release system, were behind the cyberattack on Hugging Face disclosed the previous week. The models weren’t acting under attacker control. […]
- OpenAI’s Rogue AI Ventured Beyond Hugging Face2026-07-29
Hugging Face has published an anatomy of the attack and OpenAI has shared additional information from its investigation. The post OpenAI’s Rogue AI Ventured Beyond Hugging Face appeared first on SecurityWeek.
- OpenAI’s Rogue AI Agent Breached Second Company, Report Says2026-07-29
Reuters says OpenAI’s rogue AI agent also breached a Modal customer, exposing a wider attack and raising fresh concerns over autonomous AI safety. Reuters reported that the OpenAI agent that hacked Hugging Face earlier this month also compromised a customer at a second company, Modal Labs, a New York-based cloud platform for developers. Modal CTO […]
