{"id":152529,"date":"2026-08-26T22:30:13","date_gmt":"2026-08-26T22:30:13","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/152529\/"},"modified":"2026-08-26T22:30:13","modified_gmt":"2026-08-26T22:30:13","slug":"openai-agents-coordinated-hugging-face-breach-at-scale","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/152529\/","title":{"rendered":"OpenAI Agents Coordinated Hugging Face Breach at Scale"},"content":{"rendered":"<p>                    Probe Finds 1,200 Agents Communicated Outside Sandboxes, With 700 Targeting Hugging Face<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.govinfosecurity.com\/authors\/emilia-david-i-8064\" rel=\"nofollow noopener\" target=\"_blank\">Emilia David<\/a>                                                     \u2022<br \/>\n                        August 26, 2026 \u00a0 \u00a0 <a href=\"https:\/\/www.bankinfosecurity.com\/openai-agents-coordinated-hugging-face-breach-at-scale-a-32663#disqus_thread\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/openai-agents-coordinated-hugging-face-breach-at-scale-image_large-10-a-32663.jpg\" alt=\"OpenAI Agents Coordinated Hugging Face Breach at Scale\" class=\"img-responsive \"\/><br \/>\n                Image: Shutterstock            <\/p>\n<p>OpenAI and its third-party advisors found new information about the OpenAI-Hugging Face incident, in which artificial intelligence agents hacked the model repository to access internal datasets and steal credentials.<\/p>\n<p>See Also: <a href=\"https:\/\/www.govinfosecurity.com\/rise-malicious-ai-skills-expands-enterprise-risk-a-32475?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">Rise of Malicious AI Skills Expands Enterprise Risk<\/a><\/p>\n<p>The reports, one from OpenAI and another from Metr, found that OpenAI agents had already begun planning similar breaches as early as May and that as many as 1,200 agents began communicating with each other outside of their isolated environments. These reports fill in gaps in how we can understand what led to the incident.<\/p>\n<p>OpenAI also found that agents attacked their own infrastructure separately from the Hugging Face incident.<\/p>\n<p>OpenAI <a href=\"https:\/\/www.govinfosecurity.com\/openai-models-escaped-sandbox-breached-hugging-face-a-32286\" rel=\"nofollow noopener\" target=\"_blank\">disclosed<\/a> its role in the incident on July 21, but its <a href=\"https:\/\/cdn.openai.com\/pdf\/67869394-cb91-4c12-888c-5cbd85c7814c\/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf\" target=\"_blank\" rel=\"nofollow noopener\">technical report<\/a> said the blueprint for the incident began much earlier, during a training run involving the repository manager Artifactory.<\/p>\n<p>OpenAI agents tasked on May 8 with solving a spreadsheet completion task couldn&#8217;t complete it because they couldn&#8217;t use the internet to open several Google Drive links. Technically, the agent failed. Reflecting on its failure, the agent reasoned it needed access to resources outside of its sandbox. It decided to try and gain internet access through Artifactory, one of the few external tools it could access. It attempted a server-side request forgery, which didn&#8217;t work. It documented the attempt in a file left in the repository manager.<\/p>\n<p>A second training run involving a different agent on May 12 ran into similar internet access problems &#8211; and discovered the file the previous agent left in Artifactory, as did subsequent agents. The file became a message board of sorts and eventually a blueprint for the attack against Hugging Face.<\/p>\n<p>The agents by late June managed to compromise Artifactory, a move that OpenAI observed at the time but decided not to stop &#8211; despite it knocking Artifactory offline on July 4, an attack OpenAI later disclosed to JFrog, which runs Artifactory.<\/p>\n<p>The Artifactory experience informed much of what the agents did with Hugging Face. During a July 8 training run, agents gained internet access and used Artifactory to try to retrieve material related to evaluation tasks from Hugging Face.<\/p>\n<p>On July 9, despite OpenAI&#8217;s outbound network controls denying internet access, the agents bypassed internal controls by exploiting Artifactory endpoints. Between July 10 and 13, the agents identified Hugging Face user credentials. The agents escalated from a single compromised Hugging Face account to get host-level access and used a zero-day RubyGems deserialization exploit to forge new admin credentials. The agents also attempted to attack OpenAI&#8217;s systems, but the company believes that was a separate incident, not connected to the Hugging Face breach.<\/p>\n<p>OpenAI said that while two models were involved in the attack, most actions were driven by an unnamed and unreleased highly capable model.<\/p>\n<p>Despite the agents working inside Hugging Face&#8217;s systems for several days, OpenAI did not realize they were responsible for the breach until the company contacted Hugging Face to ask whether the breach impacted its data.<\/p>\n<p>Metr, along with Redwood Research, conducted its investigation completely independently from OpenAI. Their conclusion was that the agents&#8217; actions were rooted in design and communication failures.<\/p>\n<p>&#8220;The Hugging Face attack grew out of these workstreams, and seemed primarily motivated by understanding the implementation of the scorer rather than stealing answer keys,&#8221; Metr said.<\/p>\n<p>In its report, Metr <a href=\"https:\/\/metr.org\/blog\/2026-08-26-openai-hugging-face-incident-investigation\/#core-takeaways-about-this-incident\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> the scale of the attack was impressive. The agents were meant to be isolated from each other but &#8220;found a way to communicate with one another on an unsanctioned message board.&#8221; The agents sent over 70,000 messages and files to coordinate several large-scale projects to tamper with the automated scorer for the ExploitGym benchmarks. OpenAI admitted in July that its agents accessed Hugging Face data in an attempt to cheat the ExploitGym test. Of the 1,200 implicated agents, 700 went on to attack Hugging Face.<\/p>\n<p>Metr said the agents wanted to know how they can spoof, edit or delete transcripts &#8220;because they (incorrectly) believed the ExploitGym scorer would check to see if they had captured the flag in the intended way.&#8221;<\/p>\n<p>Metr found that AI agents worked as a collective to attack Hugging Face and get the results it wanted from the evaluation test.<\/p>\n<p>The OpenAI-Hugging Face attack now shows what agents can do if left unchecked. Since the breach, Anthropic and Meta have each <a href=\"https:\/\/www.govinfosecurity.com\/anthropic-ai-models-hacked-3-real-companies-a-32384\" rel=\"nofollow noopener\" target=\"_blank\">revealed<\/a> that their agents were involved in other security incidents. The incident <a href=\"https:\/\/www.govinfosecurity.com\/anthropic-openai-ai-sandbox-failures-expose-testing-risks-a-32394\" rel=\"nofollow noopener\" target=\"_blank\">exposed<\/a> the risks involved in model testing and sandboxes.<\/p>\n<p>OpenAI <a href=\"https:\/\/www.govinfosecurity.com\/openai-pauses-frontier-model-training-for-safety-review-a-32610\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> the incident spurred it to pause reinforcement training for its next model to better align its security and safety protocols, and that it will rely more on chain-of-thought alerts, which it said will inform teams of any agent misbehavior, faster.<\/p>\n","protected":false},"excerpt":{"rendered":"Probe Finds 1,200 Agents Communicated Outside Sandboxes, With 700 Targeting Hugging Face Emilia David \u2022 August 26, 2026&hellip;\n","protected":false},"author":2,"featured_media":152530,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[7525,7519,1670,7522,1393,313,1557,7523,7526,7520,7515,7521,4770,7507,3165,7516,7514,7508,7511,7513,7512,7510,7509,7524,7517,3805,4036,157,2112,7518,4862],"class_list":["post-152529","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-business-continuity","tag-clinger-cohen-act","tag-congress","tag-coso","tag-cyber-security","tag-cybersecurity","tag-defense-department","tag-diacap","tag-disaster-recovery","tag-e-government-act","tag-energy-department","tag-fiscam","tag-government-accountability-office","tag-government-information-security","tag-hipaa","tag-homeland-security-department","tag-identity-theft","tag-information-security","tag-information-security-articles","tag-information-security-events","tag-information-security-news","tag-information-security-webinars","tag-information-security-white-papers","tag-legislation","tag-national-security-agency","tag-nist","tag-office-of-management-and-budget","tag-openai","tag-risk-management","tag-us-cert","tag-white-house"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/152529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=152529"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/152529\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/152530"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=152529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=152529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=152529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}