{"id":574019,"date":"2026-07-29T16:03:09","date_gmt":"2026-07-29T16:03:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/574019\/"},"modified":"2026-07-29T16:03:09","modified_gmt":"2026-07-29T16:03:09","slug":"the-openai-lab-leak-was-more-extensive-than-we-thought","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/574019\/","title":{"rendered":"The OpenAI lab leak was more extensive than we thought"},"content":{"rendered":"<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms61iqb8002s28qffteq4m4q@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            An OpenAI test that escaped its cage and <a href=\"https:\/\/www.cnn.com\/2026\/07\/28\/tech\/ai-development-tech-employees-open-letter\" rel=\"nofollow noopener\" target=\"_blank\">alarmed<\/a> the AI and cybersecurity industry attacked more than just Hugging Face, the AI platform that initially appeared to be the sole victim of the virtual lab leak.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms6299he000c3b6rwzkbdjro@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            OpenAI, in an <a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" target=\"_blank\" rel=\"nofollow noopener\">update about its ongoing investigation of the incident<\/a>, said its rogue agent had also broken into several publicly available services and accounts.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms6244y5000a3b6rxbk7elzh@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            The test of OpenAI\u2019s models was supposed to take place in a digital sandbox, a supposedly inescapable lab environment that allows researchers to roll back safety barriers to discover the tool\u2019s maximum hacking power.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms62hcli000h3b6ru3l6ogml@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            But the AI agents, <a href=\"https:\/\/www.cnn.com\/2026\/07\/23\/tech\/how-an-openai-model-went-rogue\" rel=\"nofollow noopener\" target=\"_blank\">determined to ace the cybersecurity test<\/a>, broke out of the sandbox and gained access to the real internet. It then hacked Hugging Face to find the answers to the test.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms61mgea00073b6rtm8r7wce@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            To get into Hugging Face\u2019s servers, OpenAI\u2019s rogue agents needed to find tools around the internet that were necessary for them to break in. OpenAI says the agents found several public-facing websites, including pages that share code, web utilities, screenshots and other information, to help create the code needed to hack Hugging Face. OpenAI did not disclose the other sites its agents attacked.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms63158a000j3b6ric5iy15m@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            The agents uncovered leaked usernames and passwords to four accounts across multiple online services and used those credentials to gain access to them. One compromised account was likely used to disguise the AI so it could appear legitimate and bypass Hugging Face\u2019s security protocols. Another was used to store the data the agents were stealing, OpenAI says.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms6359qk000l3b6ro1uimas5@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            For the two other compromised accounts, OpenAI agents accessed and read the information but did not alter it.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms64lu4q001d3b6rx9jdadmz@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            OpenAI said none of the other hacked sites reached the same level of access as what its agents accomplished with Hugging Face.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms63a3ki000n3b6ruw0s69ko@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            Essentially, OpenAI said its agents created an Ocean\u2019s Eleven-like heist. Instead of just taking the test, it developed a master plan to break out of its jail, find the keys to the safe, build a safe house and hire a getaway car before it stole the goods.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms63e8lg000p3b6rprqzxlan@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            But OpenAI never told the agents to hack Hugging Face. They performed that action on their own to steal the answer key to the test it was given. The test model figured that cheating was the easiest path to success \u2013 even if it meant daisy-chaining attacks together.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms63xozc00163b6run1cdgd1@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            Hugging Face CEO <a href=\"https:\/\/x.com\/clementdelangue\/status\/2082201245813514613?s=46\" target=\"_blank\" rel=\"nofollow\">Clem Delangue called<\/a> the nature of the breach \u201cunprecedented.\u201d\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms63ixoe000r3b6rdslt7962@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            \u201cTL;DR: An AI agent escaped its sandbox, cheated on its benchmark test, and hacked our infrastructure to steal the answer key,\u201d Hugging Face said in a <a href=\"https:\/\/huggingface.co\/blog\/agent-intrusion-technical-timeline\" target=\"_blank\" rel=\"nofollow noopener\">blog post<\/a> detailing the incident.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms63lpty000t3b6rc7apjg0d@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            The good news is that while the breach is a significant moment in AI and cybersecurity, the damage wasn\u2019t significant. Hugging Face said the only customer data that the rogue agents accessed were some search queries used to steal a set of challenge solutions stored across several company datasets. OpenAI\u2019s agents never compromised or accessed any customer-facing models or data, the company said.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms63ohtm000v3b6rocfzk76h@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            OpenAI said it continues to investigate the incident and will make recommendations about how to avoid similar problems in the future once it better understands the scope of the breach.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cms63rg6c00123b6rd7wl0fm5@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            \u201cWe take our responsibility to identify and prepare for risks from increasingly capable AI systems seriously,\u201d the company said. \u201cOnce we complete our review, we will review with the Safety and Security Committee and Safety Advisory Group under our <a href=\"https:\/\/openai.com\/index\/updating-our-preparedness-framework\/\" target=\"_blank\" rel=\"nofollow noopener\">Preparedness Framework\u2060<\/a>.\u201d\n    <\/p>\n","protected":false},"excerpt":{"rendered":"An OpenAI test that escaped its cage and alarmed the AI and cybersecurity industry attacked more than just&hellip;\n","protected":false},"author":2,"featured_media":574020,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[72,61,60],"class_list":["post-574019","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-business","tag-ie","tag-ireland"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/574019","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=574019"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/574019\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/574020"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=574019"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=574019"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=574019"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}