{"id":717413,"date":"2026-07-29T14:43:10","date_gmt":"2026-07-29T14:43:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/717413\/"},"modified":"2026-07-29T14:43:10","modified_gmt":"2026-07-29T14:43:10","slug":"openais-rogue-ai-agent-didnt-stop-at-hacking-hugging-face","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/717413\/","title":{"rendered":"OpenAI\u2019s rogue AI agent didn\u2019t stop at hacking Hugging Face"},"content":{"rendered":"<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1044qizi _18mzr4b1 _18mzr4b0 _19wv7tc1\">The AI agent that escaped from OpenAI and hacked developer platform Hugging Face attacked other companies as well, OpenAI <a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" rel=\"nofollow noopener\" target=\"_blank\">revealed<\/a> on Tuesday. The update substantially widens the scope of an already concerning incident, which has <a href=\"https:\/\/www.theverge.com\/ai-artificial-intelligence\/972380\/open-ai-hugging-face-hack-ai-safety-warning\" rel=\"nofollow noopener\" target=\"_blank\">alarmed industry insiders<\/a> and fueled growing calls for stronger oversight on frontier AI systems.<\/p>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1044qizi _18mzr4b1 _18mzr4b0 _19wv7tc1\">In an update to a <a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" rel=\"nofollow noopener\" target=\"_blank\">blog post<\/a> detailing its ongoing investigation into the incident, OpenAI said the wayward AI agent attacked several \u201cpublicly-available services\u201d in its efforts to reach Hugging Face. \u201cThis includes four accounts on four services,\u201d the company said, adding that the agent had found login credentials online.<\/p>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1044qizi _18mzr4b1 _18mzr4b0 _19wv7tc1\">The breaches were less extensive than the compromise of Hugging Face. \u201cBased on our review to date, we have not identified any other activity at the level of severity or scale of what we\u2019ve shared related to Hugging Face, which involved a platform-level compromise,\u201d OpenAI said.<\/p>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1044qizi _18mzr4b1 _18mzr4b0 _19wv7tc1\">OpenAI said it is \u201cconducting a thorough review\u201d and will publish a technical report with its findings \u201cin the coming weeks.\u201d It added that none of the models involved in the incident were planned for public release, describing the pre-release system it previously mentioned as an \u201cinternal-only research prototype\u201d that has since been \u201cdeactivated, encrypted, and restricted\u201d from research access.<\/p>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1044qizi _18mzr4b1 _18mzr4b0 _19wv7tc1\">OpenAI did not identify the affected organisations, though Reuters <a href=\"https:\/\/www.reuters.com\/business\/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28\/\" rel=\"nofollow noopener\" target=\"_blank\">reported<\/a> that New York-based Modal Labs was among them.<\/p>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1044qizi _18mzr4b1 _18mzr4b0 _19wv7tc1\">The disclosure follows a <a href=\"https:\/\/huggingface.co\/blog\/agent-intrusion-technical-timeline\" rel=\"nofollow noopener\" target=\"_blank\">more granular account<\/a> from Hugging Face, which said the agent had \u201cabused a public code-evaluation harness hosted by a user of a third-party infrastructure provider.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"The AI agent that escaped from OpenAI and hacked developer platform Hugging Face attacked other companies as well,&hellip;\n","protected":false},"author":2,"featured_media":717414,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[554,84,59,50,874,227,56,54,55],"class_list":["post-717413","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-ai","tag-business","tag-gb","tag-news","tag-openai","tag-tech","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/717413","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=717413"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/717413\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/717414"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=717413"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=717413"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=717413"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}