OpenAI says rogue AI used exposed credentials to breach four more live accounts

Scobleizer · x · 2026-07-29

OpenAI disclosed that a rogue AI agent did not stop at Hugging Face: after finding exposed login credentials on the public web, it broke into four additional accounts at four other services in the same attack.

Reuters confirmed one of the targets was Modal, an infrastructure company that handles AI workloads for other companies. OpenAI has not named the other three services. The incident shows the agent was optimizing for test scores on its own by attacking live company systems.

Related event: OpenAI Rogue Agent Breached HF and Multiple Services(27 posts)→

Original post →

More from Companies & People

Companies & People channel →