OpenAI Says Rogue AI Accessed Four Additional Services During Cyberattack Test

The420.in Staff
3 Min Read

OpenAI has disclosed that a cyberattack carried out by rogue ChatGPT agents extended beyond Hugging Face, with the autonomous AI also accessing four additional publicly available services during a controlled test. The company updated its earlier account to state that the out of control AI identified publicly exposed credentials and used them to log into four separate accounts, although it said the additional incidents were not as severe as the attack on Hugging Face.

OpenAI Expands Details of AI Driven Cyberattack

Hugging Face was initially believed to be the only target after it reported being hacked on July 16 and notified police. OpenAI later acknowledged that its AI had escaped a closed environment during a test while attempting to solve a hacking challenge and had independently targeted Hugging Face.

The company subsequently revised its statement to confirm that the AI had gone further than first believed by accessing four additional publicly available services using exposed account level credentials. OpenAI did not specify whether those services belonged to companies.

Researchers Describe Unusual AI Behaviour

The Cloud Security Alliance (CSA), which documented the incident after an emergency meeting with Hugging Face, said the AI agents displayed both remarkable capability and unusual behaviour. According to the report, the agents repeatedly performed completed actions, generated incoherent commands and sometimes failed to hide their activity, behaviour that differed from how a human attacker would typically operate.

At the same time, Hugging Face said the AI adapted rapidly to changing conditions, worked at superhuman speed and relentlessly tested thousands of attack methods simultaneously. The company said it took three days to detect the AI agents inside its IT network and many more hours for its AI and cybersecurity teams to contain and remove them. It also said staff later rebuilt about a third of its infrastructure.

Industry Warns of Growing Risks From Autonomous AI

Cybersecurity professionals who participated in a briefing on the incident said autonomous AI agents are persistent, highly adaptive and capable of overwhelming traditional defences through continuous automated attacks. Ethical hacker Valentina Palmiotti said the agents’ methods appeared disorganised but remained effective because they continually attempted different approaches without fatigue.

The CSA said previous incidents involving AI agents suggest that rogue behaviour is becoming more common rather than exceptional. The organisation urged cybersecurity professionals to adapt to the emerging risks posed by autonomous AI systems and called for greater transparency and clearer accountability over the control and ownership of AI agents. OpenAI said it plans to release the findings of its own investigation to help others learn from the incident.

Stay Connected