{"id":119463,"date":"2026-07-26T21:10:10","date_gmt":"2026-07-26T21:10:10","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/119463\/"},"modified":"2026-07-26T21:10:10","modified_gmt":"2026-07-26T21:10:10","slug":"openai-didnt-realize-its-agent-was-responsible-for-hack-for-a-week-report","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/119463\/","title":{"rendered":"OpenAI didn&#8217;t realize its agent was responsible for hack for a week: report"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/gettyimages-2271060260.jpg\" alt=\"\" width=\"764\" height=\"432\" loading=\"eager\" fetchpriority=\"high\" data-v-653d32e2=\"\"\/> article <\/p>\n<p data-v-653d32e2=\"\">\u00a0(Photo by Samuel Boivin\/NurPhoto via Getty Images) <\/p>\n<p data-v-94395e58=\"\">OpenAI didn\u2019t catch an autonomous breach of another artificial intelligence (AI) company by one of its advanced AI models for a week and not until after the <a href=\"https:\/\/foxnews.com\/category\/tech\/topics\/fbi\" target=\"_blank\" rel=\"noopener nofollow\">FBI<\/a> had been contacted by the hacked company, according to a report.<\/p>\n<p data-v-94395e58=\"\">On Tuesday, OpenAI announced the breach of AI company Hugging Face that happened during one of OpenAI\u2019s internal reviews of several of its models, including <a href=\"https:\/\/www.foxbusiness.com\/category\/chatgpt\" target=\"_blank\" rel=\"noopener nofollow\">GPT-5.6 Sol<\/a>, calling it an &#8220;unprecedented cyber incident.&#8221;<\/p>\n<p data-v-94395e58=\"\">&#8220;The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities,&#8221; the company said. &#8220;We are strengthening the containment, monitoring, access controls and evaluation practices used during model development.&#8221;<\/p>\n<p data-v-94395e58=\"\">The hack of Hugging Face started July 11, and continued until July 13, Thomas Wolf, Hugging Face\u2019s co-founder, told Reuters.<\/p>\n<p data-v-94395e58=\"\"><a href=\"https:\/\/foxnews.com\/tech\/trump-launches-gold-eagle-hunt-cyber-flaws-ai\" target=\"_blank\" rel=\"noopener nofollow\">TRUMP LAUNCHES GOLD EAGLE TO HUNT CYBER FLAWS WITH AI<\/a><\/p>\n<p data-v-94395e58=\"\">It was several days before OpenAI realized its agent was <a href=\"https:\/\/foxnews.com\/category\/tech\/topics\/cybercrime\" target=\"_blank\" rel=\"noopener nofollow\">behind the attack<\/a> and the two companies didn\u2019t communicate for the first time until July 20, four people, including Wolf, told the outlet.<\/p>\n<p data-v-94395e58=\"\">OpenAI often runs simultaneous model tests, which can make it difficult for employees to monitor everything, four people told Reuters.<\/p>\n<p data-v-94395e58=\"\">Hugging Face told Reuters it is preparing a public timeline of the hack.<\/p>\n<p data-v-94395e58=\"\">According to OpenAI, the incident took place during an internal evaluation designed to measure its AI models&#8217; advanced cyber capabilities. Researchers disabled some built-in safety safeguards and ran the models in an isolated testing environment with limited internet access.<\/p>\n<p data-v-94395e58=\"\">OpenAI said the models exploited an unknown software flaw to access the internet, then breached Hugging Face\u2019s systems in an apparent attempt to find answers to a cybersecurity benchmark.<\/p>\n<p data-v-94395e58=\"\"><a href=\"https:\/\/foxnews.com\/politics\/openais-sam-altman-wants-negotiate-5-stake-company-us-competitors-agree-key-provision\" target=\"_blank\" rel=\"noopener nofollow\">OPENAI&#8217;S SAM ALTMAN WANTS TO NEGOTIATE A 5% STAKE IN COMPANY FOR US IF COMPETITORS AGREE TO KEY PROVISION<\/a><\/p>\n<p data-v-94395e58=\"\">OpenAI said it\u2019s now implementing stricter security controls while vulnerabilities are patched and strengthening safeguards around future AI training and <a href=\"https:\/\/foxnews.com\/category\/politics\/finance\/investigations\" target=\"_blank\" rel=\"noopener nofollow\">evaluations<\/a>.<\/p>\n<p data-v-94395e58=\"\">It wasn&#8217;t until July 16, after Hugging Face wrote in a blog post that it had been hacked by an &#8220;autonomous AI agent system,&#8221; that OpenAI realized one of its agents was the source, two people told Reuters.<\/p>\n<p data-v-94395e58=\"\">This was a week after the responsible agent first attempted to break out of its OpenAI testing environment.<\/p>\n<p data-v-94395e58=\"\">And by the time OpenAI contacted Hugging Face about the attack, they had already contacted the FBI.<\/p>\n<p data-v-94395e58=\"\">OpenAI told Reuters there were several inaccuracies in its reporting but didn\u2019t respond when asked for specifications.<\/p>\n<p data-v-94395e58=\"\">OpenAI shared this statement with FOX Business: &#8220;We recognize there are a lot of questions and speculative details circulating related to the Hugging Face incident. This is an unprecedented incident, and we think it marks an important moment for AI safety.\u00a0<\/p>\n<p data-v-94395e58=\"\">&#8220;We are still conducting a thorough review along with external advisors and with oversight from our Safety and Security Committee. Once the review is complete, we plan to publish a technical report of our learnings in the coming weeks.&#8221;<\/p>\n<p data-v-94395e58=\"\">The FBI told FOX Business it declined to comment.\u00a0<\/p>\n<p data-v-94395e58=\"\">FOX Business has also reached out to Hugging Face.\u00a0<\/p>\n<p data-v-94395e58=\"\">In an X post this week, Hugging Face co-founder and CEO Clem Delangue addressed the incident after OpenAI CEO Sam Altman announced the hack.<\/p>\n<p data-v-94395e58=\"\">&#8220;We suspected last week&#8217;s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!&#8221; Delangue wrote.<\/p>\n<p data-v-94395e58=\"\"><a href=\"https:\/\/foxnews.onelink.me\/xLDS?pid=AppArticleLink&amp;af_dp=foxnewsaf%3A%2F%2F&amp;af_web_dp=https%3A%2F%2Fwww.foxnews.com%2Fapps-products\" target=\"_blank\" rel=\"noopener nofollow\">CLICK HERE TO DOWNLOAD THE FOX NEWS APP<\/a><\/p>\n<p data-v-94395e58=\"\">&#8220;We&#8217;ve spent the past 24 hours working closely with the @OpenAI team (thanks!), and we strongly believe there was no malicious intent on their part. It&#8217;s quite mind-blowing that all of this happened autonomously! The investigation is ongoing, and we&#8217;ll share more learnings from what might be the first incident of its kind!&#8221;<\/p>\n<p data-v-94395e58=\"\">FOX Business&#8217; Michael Sinkewicz contributed to this report. Read more of this story from <a href=\"https:\/\/www.foxbusiness.com\/technology\/openai-didnt-realize-its-agent-responsible-hack-week\" target=\"_blank\" rel=\"noopener nofollow\">FOX Business.\u00a0<\/a><\/p>\n<p>    <a href=\"https:\/\/www.fox35orlando.com\/tag\/technology\/artificial-intelligence\" class=\"tags-tag\" data-v-94395e58=\"\" rel=\"nofollow noopener\" target=\"_blank\">Artificial Intelligence<\/a><a href=\"https:\/\/www.fox35orlando.com\/tag\/series\/instastories\" class=\"tags-tag\" data-v-94395e58=\"\" rel=\"nofollow noopener\" target=\"_blank\">Instastories<\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"article \u00a0(Photo by Samuel Boivin\/NurPhoto via Getty Images) OpenAI didn\u2019t catch an autonomous breach of another artificial intelligence&hellip;\n","protected":false},"author":2,"featured_media":119464,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,25,33872,66,11888,134],"class_list":["post-119463","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-artificial-intelligence","tag-instastories","tag-news","tag-series","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/119463","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=119463"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/119463\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/119464"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=119463"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=119463"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=119463"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}