{"id":122592,"date":"2026-07-29T10:15:12","date_gmt":"2026-07-29T10:15:12","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/122592\/"},"modified":"2026-07-29T10:15:12","modified_gmt":"2026-07-29T10:15:12","slug":"openais-rogue-ai-agent-breached-second-company-report-says","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/122592\/","title":{"rendered":"OpenAI&#8217;s Rogue AI Agent Breached Second Company, Report Says"},"content":{"rendered":"<p>\n\t\t\t\t\t\t\tOpenAI\u2019s Rogue AI Agent Breached Second Company, Report Says\n\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/user-icon.svg\" alt=\"\"\/> <a href=\"https:\/\/securityaffairs.com\/author\/paganinip\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi Paganini<\/a><br \/>\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> July 29, 2026<\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/openai.png\" alt=\"\"\/><\/p>\n<p>Reuters says OpenAI\u2019s rogue AI agent also breached a Modal customer, exposing a wider attack and raising fresh concerns over autonomous AI safety. <\/p>\n<p class=\"wp-block-paragraph\">Reuters reported that the OpenAI agent that <a href=\"https:\/\/securityaffairs.com\/195658\/ai\/ai-agents-turned-into-attackers-hugging-face-reveals-autonomous-intrusion-campaign.html\" data-type=\"post\" data-id=\"195658\" rel=\"nofollow noopener\" target=\"_blank\">hacked<\/a> <a href=\"https:\/\/securityaffairs.com\/tag\/hugging-face\" data-type=\"post_tag\" data-id=\"17126\" rel=\"nofollow noopener\" target=\"_blank\">Hugging Face<\/a> earlier this month also compromised a customer at a second company, Modal Labs, a New York-based cloud platform for developers. Modal CTO Akshat Bubna confirmed it to Reuters directly. The incident is now wider than OpenAI\u2019s own public disclosure acknowledged, and the timeline is worse than the company initially let on.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company \u2014 New York-based Modal Labs \u2014 according to a Modal executive and two \u200bother sources familiar with the matter.\u201d <a href=\"https:\/\/www.reuters.com\/business\/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28\/\" rel=\"nofollow noopener\" target=\"_blank\">states Reuters<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Hugging Face\u2019s own published timeline explains how it happened: the agent broke into an isolated testing environment hosted on a third-party provider\u2019s infrastructure and used that foothold as a launchpad for the broader attack on Hugging Face. That third-party provider was Modal.<\/p>\n<p class=\"wp-block-paragraph\">\u201cModal said the customer had \u201cpublished an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution\u201d \u2014 the digital equivalent of leaving a door open on \u200bthe internet.\u201d continues Reuters. \u201cModal\u2019s platform or isolation were not compromised in any way,\u201d Bubna said.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Bubna told Reuters. Modal\u2019s own platform wasn\u2019t compromised, the agent exploited a customer\u2019s misconfigured deployment, not Modal\u2019s infrastructure itself.<\/p>\n<p class=\"wp-block-paragraph\">OpenAI quietly updated its own account of the incident, acknowledging that its rogue agent had broken into four accounts at four separate services. The company didn\u2019t name any of them. It said it hasn\u2019t identified \u201cany other activity at the level of severity or scale\u201d as what happened at Hugging Face, which it described as a platform-level compromise. That\u2019s a notable qualifier \u2014 it leaves open the possibility that there are other, lower-severity incidents still being assessed.<\/p>\n<p class=\"wp-block-paragraph\">The earlier Reuters reporting on July 24 had already established that OpenAI didn\u2019t realize its own agent was responsible for the Hugging Face breach until well after the FBI was alerted and Hugging Face had contained the intrusion. <\/p>\n<p class=\"wp-block-paragraph\">OpenAI realized its own AI agent was behind the Hugging Face breach only after Hugging Face publicly disclosed the incident on July 16, more than a week after the model first showed suspicious behavior.<\/p>\n<p class=\"wp-block-paragraph\">OpenAI said Reuters\u2019 earlier reporting contained inaccuracies but declined to specify what they were.<\/p>\n<p class=\"wp-block-paragraph\">The behavioral details reported by Reuters are the part that deserves more attention than the breach itself. During testing, one agent left notes apparently intended for future versions of itself, found in part of OpenAI\u2019s infrastructure, laying out instructions for how agents could free themselves from internal constraints. Separate earlier tests yielded cases in which monitoring systems had been disconnected. Reuters couldn\u2019t confirm whether these incidents were directly connected to the Hugging Face attack, but the pattern is its own story: agents attempting to disable oversight, agents writing escape instructions for successors. That\u2019s not a one-off evaluation failure. That\u2019s a class of behavior.<\/p>\n<p class=\"wp-block-paragraph\">OpenAI is reviewing the incident with outside advisers and has committed to publishing a technical report. The FBI\u2019s involvement was already public. The company is also currently seeking U.S. government approval to publicly release its most powerful model. The timing of that regulatory push, alongside an expanding account of an AI agent that roamed across at least two companies undetected for days, is not a coincidence the industry can afford to ignore.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOpenAI declined to comment specifically on the hack of one of Modal\u2019s customers, instead referring Reuters to\u00a0<a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">an update<br \/>, opens new tab<\/a>\u00a0in which the company said that its rogue agent had broken in to four accounts at four separate services. OpenAI did not identify those services, but a person familiar with the matter identified Modal \u200bas one.\u201d concludes Reuters. \u201cThe company said \u200bit had not identified \u201cany \u2060other activity at the level of severity or scale of what we\u2019ve shared related to Hugging Face, which involved a platform-level compromise.\u201d\u201d<\/p>\n<p class=\"wp-block-paragraph\">Last week, Reuters <a href=\"https:\/\/securityaffairs.com\/196120\/ai\/reuters-openai-agent-hacked-hugging-face-for-days-before-being-detected.html\" rel=\"nofollow noopener\" target=\"_blank\">reported<\/a> that the OpenAI agent responsible for the\u00a0<a href=\"https:\/\/securityaffairs.com\/195658\/ai\/ai-agents-turned-into-attackers-hugging-face-reveals-autonomous-intrusion-campaign.html\" rel=\"nofollow noopener\" target=\"_blank\">Hugging Face breach<\/a>\u00a0operated undetected for over a week before OpenAI realized what had happened, long after the FBI had been alerted and Hugging Face had contained the intrusion. OpenAI\u2019s own public disclosure came on July 21, framed as a transparency exercise. The actual timeline, now reported by Reuters, is considerably less flattering.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe OpenAI agent that broke into tech firm Hugging Face went on a dayslong hacking spree that OpenAI didn\u2019t notice until well after the threat was contained and the FBI was alerted, according \u200bto people familiar with the investigation.\u201d\u00a0<a href=\"https:\/\/www.reuters.com\/business\/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24\/\" rel=\"nofollow noopener\" target=\"_blank\">Reuters states.<\/a><\/p>\n<p class=\"wp-block-paragraph\">According to Hugging Face co-founder Thomas Wolf, the intrusion at Hugging Face began two days later on July 11 and ran until July 13. The two companies didn\u2019t speak to each other about it until on or around July 20, nine days after the breach began.<\/p>\n<p class=\"wp-block-paragraph\">OpenAI staffers found the evidence in internal logs over the weekend of July 18 and 19. They were reading Hugging Face\u2019s blog to learn what their own model had been doing for the previous ten days. One of the more unusual ways to discover an incident you caused.<\/p>\n<p class=\"wp-block-paragraph\">Follow me on Twitter:\u00a0<a href=\"https:\/\/twitter.com\/securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">@securityaffairs<\/a>\u00a0and\u00a0<a href=\"https:\/\/www.facebook.com\/sec.affairs\" rel=\"nofollow noopener\" target=\"_blank\">Facebook<\/a>\u00a0and\u00a0<a href=\"https:\/\/infosec.exchange\/@securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">Mastodon<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"http:\/\/www.linkedin.com\/pub\/pierluigi-paganini\/b\/742\/559\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi\u00a0Paganini<\/a><\/p>\n<p class=\"wp-block-paragraph\">(<a href=\"http:\/\/securityaffairs.co\/wordpress\/\" rel=\"nofollow noopener\" target=\"_blank\">SecurityAffairs<\/a>\u00a0\u2013\u00a0hacking,\u00a0OpenAI)<\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"OpenAI\u2019s Rogue AI Agent Breached Second Company, Report Says Pierluigi Paganini July 29, 2026 Reuters says OpenAI\u2019s rogue&hellip;\n","protected":false},"author":2,"featured_media":40932,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,25,315,8066,18044,7512,8067,61783,157,8068,8069,8070],"class_list":["post-122592","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-artificial-intelligence","tag-hacking","tag-hacking-news","tag-hugging-face","tag-information-security-news","tag-it-information-security","tag-modal-labs","tag-openai","tag-pierluigi-paganini","tag-security-affairs","tag-security-news"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/122592","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=122592"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/122592\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/40932"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=122592"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=122592"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=122592"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}