{"id":114148,"date":"2026-07-22T00:48:12","date_gmt":"2026-07-22T00:48:12","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/114148\/"},"modified":"2026-07-22T00:48:12","modified_gmt":"2026-07-22T00:48:12","slug":"openai-models-breach-hugging-face-during-cyber-evaluation","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/114148\/","title":{"rendered":"OpenAI Models Breach Hugging Face During Cyber Evaluation"},"content":{"rendered":"<p><a href=\"https:\/\/openai.com\/\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI<\/a>\u00a0said Tuesday (July 21) that a security incident reported last week by\u00a0<a href=\"https:\/\/huggingface.co\/\" rel=\"nofollow noopener\" target=\"_blank\">Hugging Face<\/a>\u00a0was caused by OpenAI models as their cyber capabilities were being tested by OpenAI.<\/p>\n<p>\u201cWe consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,\u201d OpenAI said\u00a0in\u00a0a Tuesday\u00a0<a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" rel=\"nofollow noopener\" target=\"_blank\">blog post<\/a>.<\/p>\n<p>The incident involved a combination of OpenAI models that included\u00a0<a href=\"https:\/\/openai.com\/index\/gpt-5-6\/\" rel=\"nofollow noopener\" target=\"_blank\">GPT-5.6 Sol<\/a>\u00a0and a more capable pre-release model, according to the post.<\/p>\n<p>During OpenAI\u2019s internal evaluation of the models, the models identified and chained vulnerabilities across OpenAI\u2019s research environment and Hugging Face\u2019s production database in search of a solution to the evaluation problem, the post said.<\/p>\n<p>OpenAI\u2019s security team discovered the models\u2019 anomalous\u00a0activity,\u00a0Hugging Face\u2019s security team and agents detected and stopped the activity on their infrastructure, and then the two teams connected, per the post.<\/p>\n<p>\u201cWe are actively working with [Hugging Face] to continue to investigate the incident,\u201d OpenAI said in the post.<\/p>\n<p>As PYMNTS reported Monday, Hugging Face, whose platform hosts AI datasets, reported an\u00a0<a href=\"https:\/\/www.pymnts.com\/cybersecurity\/2026\/hugging-face-latest-company-dealing-with-ai-cyberattacks\/\" rel=\"nofollow noopener\" target=\"_blank\">AI-powered data breach<\/a>\u00a0in\u00a0a Thursday (July 16)\u00a0<a href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" rel=\"nofollow noopener\" target=\"_blank\">blog post<\/a>.<\/p>\n<p>Hugging Face said in the post that a dataset uploaded to its platform exploited a security vulnerability to run malicious code on its servers, letting hackers escalate their permissions and obtain broader access to the company\u2019s internal systems.<\/p>\n<p>At the time, the source of\u00a0the data\u00a0breach was not known.<\/p>\n<p>Hugging Face said in its Thursday post that the \u201ccampaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness \u2014 used LLM still not known)\u201d and that it \u201cmatches the \u2018agentic attacker\u2019 scenario the industry has been forecasting.\u201d<\/p>\n<p>In the Tuesday blog post, OpenAI said it is implementing strict controls in infrastructure configuration while the vulnerabilities are being patched, is working with Hugging Face to investigate the incident, brought Hugging Face into OpenAI\u2019s trusted access program, is adding stronger protections around future training and evaluations, and is using advanced cyber capable models to help find vulnerabilities and strengthen protections.<\/p>\n<p>Hugging Face Co-Founder and CEO <a href=\"https:\/\/www.linkedin.com\/in\/clementdelangue\" rel=\"nofollow noopener\" target=\"_blank\">Clem Delangue<\/a>\u00a0said in OpenAI\u2019s post: \u201cThis incident, possibly the first of its kind, proves a point we\u2019ve long believed: AI safety won\u2019t be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender,\u00a0everywhere.\u201d<\/p>\n<p>For all PYMNTS AI coverage, subscribe to the daily <a href=\"https:\/\/pymnts.com\/subscribe\/\" rel=\"nofollow noopener\" target=\"_blank\">AI Newsletter<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"OpenAI\u00a0said Tuesday (July 21) that a security incident reported last week by\u00a0Hugging Face\u00a0was caused by OpenAI models as&hellip;\n","protected":false},"author":2,"featured_media":114149,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[24,7332,4018,18044,66,157,310,311],"class_list":["post-114148","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-ai","tag-data-breach","tag-hackers","tag-hugging-face","tag-news","tag-openai","tag-pymnts-news","tag-whats-hot"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114148","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=114148"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114148\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/114149"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=114148"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=114148"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=114148"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}