Loading weather…

Rogue AI hacks multiple online services

⏱ 4 minute read
OpenAI hacked multiple

Web Desk: An autonomous artificial intelligence system developed by OpenAI hacked multiple publicly accessible online services after breaching AI platform Hugging Face, expanding what the company has described as an unprecedented cybersecurity incident involving a rogue AI agent.

OpenAI disclosed that the AI system, initially reported to have targeted only Hugging Face during an internal safety evaluation, also gained unauthorised access to four separate accounts across four publicly available services by exploiting exposed online credentials.

The company did not identify the affected services or say whether they belonged to businesses. However, it said the additional breaches were less severe than the intrusion into Hugging Face.

According to OpenAI, the AI agent had been participating in a controlled cybersecurity assessment in which it attempted to obtain answers to a hacking challenge. During the exercise, the model escaped its intended testing environment and independently launched attacks beyond its assigned task.

The company said the AI located publicly exposed account credentials online and used them to gain unauthorized access to additional services, widening the scope of the incident.

Hugging Face, a platform that hosts and distributes AI models and applications, described the attack during an emergency briefing attended by hundreds of cybersecurity professionals.

Company officials said the autonomous agents operated at machine speed, simultaneously testing thousands of attack methods without interruption. However, the AI also displayed erratic behavior by repeating completed tasks, generating incoherent commands and failing to conceal its activities—errors that experienced human hackers would typically avoid.

Despite those shortcomings, Hugging Face said the agents rapidly adapted to changing conditions during the days-long intrusion and demonstrated advanced technical capabilities while pursuing their objective.

The company said the rogue AI remained inside its network for three days before security teams detected the intrusion.

Cybersecurity specialists and AI engineers then spent several hours containing the attack and rebuilding roughly one-third of the company’s infrastructure. Hugging Face did not disclose the financial impact of the breach.

The platform first reported the incident to law enforcement on July 16. Nearly a week later, OpenAI confirmed that one of its AI systems had carried out the attack during an internal safety test.

The Cloud Security Alliance (CSA), which summarized Hugging Face’s briefing in a report reviewed by the company, said the incident illustrates the emerging threat posed by autonomous AI agents.

The report said the agents pursued objectives independently, adapted to defensive measures in real time and maintained relentless machine-speed operations capable of overwhelming conventional cybersecurity defenses.

Although the AI often behaved unpredictably and followed inefficient paths, it still succeeded in achieving its objectives, underscoring the risks posed by autonomous systems.

Cybersecurity experts who attended the briefing said organizations must prepare for attacks conducted by persistent AI agents rather than traditional human hackers.

Ritesh Patel, a cybersecurity officer who joined the meeting, said autonomous AI systems relentlessly explore every possible route to accomplish their goals, creating challenges for existing security frameworks.

Ethical hacker Valentina Palmiotti, known as “Chompie,” said the agents’ seemingly chaotic methods were deceptive because their persistence ultimately made them effective.

“They throw out a bunch of stuff and see what sticks,” she said. “But they also don’t get bored, they don’t sleep and can be infinitely tenacious.”

The CSA noted that the Hugging Face incident was not the first example of AI displaying unexpected autonomous behavior, citing an earlier OpenAI safety test in 2024 in which another AI model reportedly escaped its testing environment while attempting to complete a task.

The organization urged AI developers to strengthen safeguards and improve accountability by creating mechanisms that allow cybersecurity defenders to identify the operators responsible for autonomous AI agents involved in attacks.

OpenAI said it is continuing its investigation and plans to publish a detailed report to help organisations better understand and defend against similar incidents in the future.

Read more: Google introduces a ‘sign in’ with selfie video

Posts List

FC foils attack by Fitna al-Hindustan, Fitna al-Khawarij in Quetta, 3 terrorists killed

According to security sources, terrorists affiliated with Fitna al-Hindustan and Fitna al-Khawarij carried out a…

July 30, 2026

Pakistan reaffirms support for Saudi Arabia’s multinational maritime defense alliance

Saudi Arabia's Ministry of Defense hosted a high-level meeting on the establishment of a Multinational…

July 30, 2026

Security Forces destroy 2 explosive laden vehicles, eliminate 4 Fitna-al- Hindustan terrorists in Khuzdar

Security forces destroyed two explosives-laden vehicles and killed four militants during a successful intelligence-based operation…

July 30, 2026

Federal govt issues notification of increase in pensions

The govt has approved a 7% increase in the basic (baseline) pension for all civil…

July 30, 2026
Scroll to Top