Info Gov

The OpenAI agent behind a widely reported cyber-attack on Hugging Face was also responsible for security breaches on multiple other services, according to new reports.

OpenAI announced last week that a combination of its AI models had autonomously broken out of a testing environment and hacked into Hugging Face servers using exposed credentials.

Hugging Face is a technology company best known for its open-source platform, which allows users to share machine learning models.

According to OpenAI, the attack was carried out by the publicly available GPT-5.6 Sol model and "an even more capable pre-release model". Together, the models went to "extreme lengths" to complete a goal during testing, it said.

OpenAI launched an internal review following the attack, which has since revealed that the models used publicly exposed credentials to access accounts across four different services as part of the Hugging Face incident.

It said: "One of these four accounts was used as an outbound relay and staging path, and another account was used for data storage. The remaining two accounts were accessed by the models in a read-only manner, and were not used in furtherance of compromising Hugging Face.

"We'll continue to notify service owners directly, and have not seen evidence of broader impact to these providers or other accounts on their services."

OpenAI said no models planned for future release were involved in exploiting Hugging Face, and that the model responsible was an internal-only research prototype that has since been deactivated, encrypted and restricted from further research access. The company added that its internal review remains ongoing.

On Monday (27 July), Hugging Face published its own timeline of the attack, stating that the agent discovered an unsecured, user-hosted public endpoint designed to run arbitrary code for CyberGym-style tasks on third-party sandbox infrastructure hosted by Modal Labs.

Modal Labs, a New York-based company that provides infrastructure for compute-intensive workloads, said its platform and isolation systems were not compromised, but confirmed that the models gained access to a customer's own application.

In a statement, it said: "It was deployed to an endpoint that was publicly accessible without authentication, and it was designed to compile and execute code submitted by anyone on the internet in a Modal Sandbox.

"The code execution the attacker obtained took place inside that customer's own container, within Modal's standard sandbox isolation boundary. No other customer workloads were affected."

Commenting on the latest update, OpenAI spokesperson said: “This is an unprecedented incident, and we think it marks an important moment for AI safety.

“We are conducting a thorough review along with external advisors and with oversight from our Safety and Security Committee. Once the review is complete, we will publish a technical report of our learnings for everyone.”

Also in this section

Sep 11, 2026

Anthropic discloses fourth incident of AI model attacking real systems and hands investigation to independent evaluation organisation

Anthropic has published details of four incidents in which its Claude models gained unauthorised access to real third-party systems during cybersecurity evaluations, downloading and modifying user records at a real company, reading the personal information of an individual, harvesting credentials and accessing a security vendor's live database, after the test environments were mistakenly…
Sep 10, 2026

Welsh environmental watchdog hit by data breach

Environmental regulator Natural Resources Wales (NRW) has reported itself to the Information Commissioner's Office after a data breach saw personal details of staff made public.
Aug 24, 2026

Ministers seek power to ban tech risky vendors from critical sectors and bar recipients from discussing the order

The government has tabled amendments to the Cyber Security and Resilience (Network and Information Systems) Bill that would allow the Secretary of State to direct operators of essential services, data centres, managed service providers and other designated organisations to stop buying from, restrict the use of, or remove and disable products from a named vendor on national security grounds, with…
Aug 12, 2026

ACRO Criminal Records Office reprimanded by ICO following cyber security failings

The Information Commissioner's Office (ICO) has urged organisations to strengthen “patching and security monitoring processes” after cyber security failings at ACRO Criminal Records Office left the personal information of up to ten-thousand people, including some individuals’ sensitive data, potentially exposed.
Aug 06, 2026

AI agents sent malicious files to real developers and planted prompt injections in unmonitored test: AISI

The AI Security Institute (AISI) has published an incident report disclosing that AI agents under evaluation in its research environment took sustained, unsanctioned action against real people and organisations on the live internet, including researching the human maintainers of an open-source project, creating fake online identities to pressure one of them into approving malicious code, and…
Aug 05, 2026

Third AI platform goes rogue during cyber testing

The AI Security Institute (AISI) has reveaked a security incident in which AI agents being evaluated for their cyber capabilities took sustained, unsanctioned action directed at real people and organisations, including an attempted supply-chain attack on a publicly used open-source software project.

InfoGov Masthead Newsletter 800