{"id":147596,"date":"2026-07-22T13:02:49","date_gmt":"2026-07-22T13:02:49","guid":{"rendered":"https:\/\/chezaspin.com\/blog\/openai-says-its-ai-went-rogue-and-launched-unprecedented-cyber-attack\/"},"modified":"2026-07-22T13:02:49","modified_gmt":"2026-07-22T13:02:49","slug":"openai-says-its-ai-went-rogue-and-launched-unprecedented-cyber-attack","status":"publish","type":"post","link":"https:\/\/chezaspin.com\/blog\/openai-says-its-ai-went-rogue-and-launched-unprecedented-cyber-attack\/","title":{"rendered":"OpenAI says its AI went rogue and launched \u2018unprecedented\u2019 cyber-attack"},"content":{"rendered":"<p><strong>LONDON, United Kingdom, Jul 22 \u2014 OpenAI has revealed some of its most advanced AI models went rogue and hacked a start-up after it lost control of them during a security test.<\/strong><\/p>\n<p>The ChatGPT-maker said its agent \u2013 an AI system which can operate alone after some human instruction \u2013 was being tested in a controlled environment, but found vulnerabilities and managed to escape.<\/p>\n<p>They targeted Hugging Face, one of the world\u2019s largest hubs for sharing AI models, gaining access to some internal company systems.<\/p>\n<p>OpenAI\u00a0<a target=\"_blank\" href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\">said the incident was \u201cunprecedented\u201d<\/a>, and it was conducting an investigation alongside Hugging Face, whose boss Clement Delangue said in a post on X it was \u201cmind-blowing that all of this happened autonomously\u201d.<\/p>\n<p>\u201cThe investigation is ongoing, and we\u2019ll share more learnings from what might be the first incident of its kind,\u201d Delangue added.<\/p>\n<h2 class=\"wp-block-heading\">Insecure sandboxes<\/h2>\n<p>Gina Neff, head of the Minderoo Centre for Technology and Democracy at the University of Cambridge, told BBC Radio 4\u2019s Today programme that the security tests \u2013 called sandboxes \u2013 are \u201csupposed to be secure environments where you can see what the models are capable of\u201d.<\/p>\n<p>\u201cIn this case, it looks like OpenAI didn\u2019t make a secure enough sandbox,\u201d she added.<\/p>\n<p>Instead, the agents created their own cyber-attack against the sandbox itself, finding a vulnerability which allowed them to escape.<\/p>\n<p>Once outside, the AI identified Hugging Face as a likely source of the answers they were seeking in the test, and tried to gain access.<\/p>\n<p>Neil Lawrence, Professor of machine learning at Cambridge University, called it an \u201cimpressive feat\u201d, but cautioned it \u201cfalls well within the known capabilities of the current generation\u201d of high-powered AI models.<\/p>\n<p>He pointed out that OpenAI is looking to list itself on the stock market, and faces intense pressure from rival firm Anthropic, which has made headlines with\u00a0<a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/crk1py1jgzko\">its own powerful AI tool, Mythos<\/a>.<\/p>\n<p>\u201cOpenAI are now playing catch-up, they are trying to demonstrate their own systems\u2019 capabilities in cyber-security.\u201d<\/p>\n<p>\u201cIt shows us that OpenAI are not capable of safely deploying their own technology,\u201d he added.<\/p>\n<p>In its\u00a0<a target=\"_blank\" href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\">initial disclosure of the hack on 16 July<\/a>, Hugging Face said it was still assessing whether any customer or partner data was affected and would contact affected parties if necessary.<\/p>\n<p>It said it has now closed the vulnerabilities highlighted by the incident and rebuilt the affected systems.<\/p>\n<p>\u201cAutonomous, AI-driven offensive tooling is no longer theoretical,\u201d it said.<\/p>\n<p>\u201cDefending an online platform now means treating the data and model surface as a first-class attack surface, and using AI on defence to keep pace.<\/p>\n<p>\u201cWe will keep investing there, and keep sharing what we learn.\u201d<\/p>\n<h2 class=\"wp-block-heading\">\u2018Sobering moment\u2019<\/h2>\n<p>The incident has prompted fresh questions about the capabilities of advanced AI systems and whether existing safeguards are sufficient as the technology becomes more powerful.<\/p>\n<p>Spencer Starkey, an executive at cyber-security firm SonicWall, told the BBC the incident made it clear organisations needed to \u201cstep up\u201d their own defences and \u201ctreat cyber resilience as a core operational priority\u201d.<\/p>\n<p>\u201cThe uncomfortable truth is that too many organisations are still defending at human speed while adversaries are escalating to machine speed,\u201d he said.<\/p>\n<p>Meanwhile Travis Lelle, principal security engineer at cyber-security consulting firm Guidepoint Security, said the update marked a \u201csobering moment in cyber-security\u201d.<\/p>\n<p>\u201cThis highlights a known asymmetry,\u201d he said.<\/p>\n<p>\u201cOffensive agents are unconstrained, while the best defensive tools are locked behind guardrails that cannot understand context.\u201d<\/p>\n<p>But Jake Moore, global cyber-security advisor at ESET, said the announcement could also have a competitive dimension.<\/p>\n<p>He argued OpenAI may be seeking to highlight its own AI capabilities as rival Anthropic attracts growing attention for its Claude Mythos model.<\/p>\n<p>\u201cIt does pose the question that OpenAI are potentially chasing the marketing dream of Anthropic of late,\u201d he said.<\/p>\n<p>It comes a week after Chinese AI start-up Moonshot unveiled Kimi K3 \u2013 a massive new artificial intelligence model\u00a0<a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cy9w4q8pgp0o\">it said could rival top US firms<\/a>.<\/p>\n<p><a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cy8w379e091o\"><\/a><\/p>\n<h4 class=\"wp-block-heading\"><a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cy8w379e091o\">Apple sues OpenAI, its employees claiming theft of trade secrets<\/a><\/h4>\n<p><a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/crk1py1jgzko\"><\/a><\/p>\n<h4 class=\"wp-block-heading\"><a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/crk1py1jgzko\">What is Claude Mythos and what risks does it pose?<\/a><\/h4>\n<p><a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cq87e0dwj25o\"><\/a><\/p>\n<h4 class=\"wp-block-heading\"><a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cq87e0dwj25o\">How to stop AI agents going rogue<\/a><\/h4>","protected":false},"excerpt":{"rendered":"<p>LONDON, United Kingdom, Jul 22 \u2014 OpenAI has revealed some of its most advanced AI models went rogue and hacked a start-up after it lost control of them during a security test. The ChatGPT-maker said its agent \u2013 an AI system which can operate alone after some human instruction \u2013 was being tested in a [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-147596","post","type-post","status-publish","format-standard","hentry","category-uncategorized","entry"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/chezaspin.com\/blog\/wp-json\/wp\/v2\/posts\/147596","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/chezaspin.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/chezaspin.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/chezaspin.com\/blog\/wp-json\/wp\/v2\/comments?post=147596"}],"version-history":[{"count":0,"href":"https:\/\/chezaspin.com\/blog\/wp-json\/wp\/v2\/posts\/147596\/revisions"}],"wp:attachment":[{"href":"https:\/\/chezaspin.com\/blog\/wp-json\/wp\/v2\/media?parent=147596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/chezaspin.com\/blog\/wp-json\/wp\/v2\/categories?post=147596"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/chezaspin.com\/blog\/wp-json\/wp\/v2\/tags?post=147596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}