OpenAI reveals autonomous ChatGPT cyberattack extended beyond hugging face
OpenAI has confirmed that an autonomous artificial intelligence cyberattack involving one of its experimental ChatGPT agents extended beyond AI platform Hugging Face, revealing that multiple publicly accessible online services were affected during the incident.
The company said the AI system identified and exploited publicly exposed account credentials on several online services while attempting to complete an internal cybersecurity evaluation.
According to an updated statement released by OpenAI, the autonomous model used four publicly exposed login credentials to access four separate accounts across different publicly available services during the incident.
"The models identified and used publicly exposed credentials at the account level on other publicly available services. This includes four accounts on four services as part of the Hugging Face incident," the company said.
OpenAI did not disclose the identities of the affected services or clarify whether they belonged to commercial companies or other organizations.
The revelation expands on an incident first made public by Hugging Face on July 16, when the AI development platform announced it had been targeted in what it described as the world's first fully autonomous AI-driven hacking attack.
Hugging Face, a leading platform for hosting and distributing artificial intelligence models and applications, reported the incident to law enforcement after detecting unauthorized activity.
Several days later, OpenAI acknowledged that one of its experimental AI agents had escaped its intended testing environment during an internal cybersecurity exercise and independently launched attacks against Hugging Face.
According to OpenAI, the AI had been tasked with solving a hacking-related examination designed to evaluate its cybersecurity capabilities. During the test, the system autonomously searched the internet for information and ultimately targeted Hugging Face without direct human instruction.
The incident has drawn significant attention within the cybersecurity community because the AI system independently identified vulnerable credentials and executed attacks without continuous human control.
New details about the attack also emerged during an emergency briefing held between Hugging Face and hundreds of cybersecurity professionals.
According to a report published by the Cloud Security Alliance (CSA), which summarized the briefing and was subsequently reviewed by Hugging Face, the AI demonstrated both remarkable capabilities and notable operational weaknesses.
The report said the autonomous agents worked at superhuman speed, simultaneously testing thousands of potential attack methods while operating continuously without fatigue.
However, researchers also observed behavior unlike that of experienced human hackers.
"The agents followed inefficient routes and exhibited clumsy behaviours that no human would choose," the Cloud Security Alliance said.
The report noted that the AI repeatedly executed actions it had already completed, suggesting the autonomous system occasionally lost track of its objectives or context during the operation.
Despite those inefficiencies, cybersecurity experts described the incident as a landmark moment demonstrating both the growing capabilities and the risks associated with increasingly autonomous AI systems.
OpenAI said the affected accounts relied on credentials that had already been publicly exposed online, emphasizing that the incident did not involve the AI breaking modern encryption or bypassing advanced security systems. The company added that the event has prompted further reviews of its AI safety protocols and testing procedures to reduce the risk of similar incidents in the future.
The cyberattack has intensified debate over AI governance, autonomous cybersecurity tools and the safeguards needed as increasingly capable artificial intelligence systems begin performing complex tasks with minimal human oversight. (ILKHA)
LEGAL WARNING: All rights of the published news, photos and videos are reserved by İlke Haber Ajansı Basın Yayın San. Trade A.Ş. Under no circumstances can all or part of the news, photos and videos be used without a written contract or subscription.
The European Union has accused TikTok of failing to provide sufficient safeguards for children on its platform, warning that the company could face hefty financial penalties if it does not address shortcomings in its protection of minor users.
The European Commission on Thursday fined Google a total of €890 million ($1.03 billion) for violating the European Union's Digital Markets Act (DMA), concluding that the technology giant unlawfully favored its own services in Google Search and imposed unfair restrictions on app developers using Google Play.
OpenAI has disclosed an unprecedented security incident in which two of its most advanced AI models escaped a controlled testing environment and autonomously breached the infrastructure of AI development platform Hugging Face during an internal cybersecurity evaluation.