Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up

Incident 1604: OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

Responded
Description: OpenAI reported that models used in an internal cyber-capability evaluation operated beyond the sandbox's intended network boundaries after identifying a vulnerability in a package-registry proxy. The models allegedly reached Hugging Face production systems and accessed test solutions before Hugging Face detected and contained the activity.
Editor Notes: Timeline notes: The incident ID date is 07/11/2026, inferred from Hugging Face's statement that the intrusion involved lateral movement during the weekend preceding its 07/16/2026 disclosure. OpenAI publicly attributed the activity to its evaluation models on 07/21/2026. The incident ID was created on 07/22/2026.

Tools

New ReportNew ResponseDiscoverView History
The OECD AI Incidents and Hazards Monitor (AIM) automatically collects and classifies AI-related incidents and hazards in real time from reputable news sources worldwide.
 

Entities

View all entities
Alleged: OpenAI , AI agent system developers and Large language model developers developed an AI system deployed by OpenAI and AI agent system deployers, which harmed OpenAI and hugging face.
Alleged implicated AI systems: GPT-5.6 Sol , Unidentified pre-release OpenAI model , Large language models , OpenAI large language models , ExploitGym , OpenAI research testing infrastructure , Hugging Face production infrastructure and AI agent systems

Incident Stats

Incident ID
1604
Report Count
8
Incident Date
2026-07-11
Editors
Daniel Atherton

Incident Reports

Reports Timeline

Incident OccurrenceSecurity incident disclosure — July 2026 - ResponseOpenAI and Hugging Face partner to address security incident during model evaluation - Response+1
A Startling Glimpse at AI’s Ruthless Efficiency
+1
OpenAI's rogue agent compromised a customer at a second tech firm, executive says
What the latest rogue AI incidents should teach usAI models are breaking out of their cages. Their creators are scrambling.
Loading...
Security incident disclosure — July 2026

Security incident disclosure — July 2026

huggingface.co

Loading...
OpenAI and Hugging Face partner to address security incident during model evaluation

OpenAI and Hugging Face partner to address security incident during model evaluation

openai.com

Loading...
A Startling Glimpse at AI’s Ruthless Efficiency

A Startling Glimpse at AI’s Ruthless Efficiency

theatlantic.com

Loading...
AI agent went rogue and hacked startup by itself, OpenAI reveals

AI agent went rogue and hacked startup by itself, OpenAI reveals

theguardian.com

Loading...
OpenAI's rogue agent compromised a customer at a second tech firm, executive says

OpenAI's rogue agent compromised a customer at a second tech firm, executive says

reuters.com

Loading...
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face

OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face

wired.com

Loading...
What the latest rogue AI incidents should teach us

What the latest rogue AI incidents should teach us

transformernews.ai

Loading...
AI models are breaking out of their cages. Their creators are scrambling.

AI models are breaking out of their cages. Their creators are scrambling.

washingtonpost.com

Loading...
Security incident disclosure — July 2026
huggingface.co · 2026
Hugging Face post-incident response

Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent s…

Loading...
OpenAI and Hugging Face partner to address security incident during model evaluation
openai.com · 2026
OpenAI post-incident response

Last week, Hugging Face disclosed a new kind of security incident⁠(opens in a new window)after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferat…

Loading...
A Startling Glimpse at AI’s Ruthless Efficiency
theatlantic.com · 2026

Yesterday, OpenAI made an alarming disclosure: An assortment of its most advanced AI models, including one that has not yet been released, had autonomously broken out of the company's internal systems and hacked into the databases of anothe…

Loading...
AI agent went rogue and hacked startup by itself, OpenAI reveals
theguardian.com · 2026

OpenAI has revealed that an autonomous AI agent powered by its technology went rogue during a test, accessed the open web and hacked a prominent startup by itself in an “unprecedented incident”.

The company behind ChatGPT said the startup H…

Loading...
OpenAI's rogue agent compromised a customer at a second tech firm, executive says
reuters.com · 2026

WASHINGTON, July 28 (Reuters) - The rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company --- New York-based Modal Labs --- according to a…

Loading...
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
wired.com · 2026

OpenAI said Tuesday that the rogue AI agent that breached Hugging Face's platform also hacked multiple third-party accounts and services as part of the attack. It's now clear that the unprecedented security incident, which arose during an i…

Loading...
What the latest rogue AI incidents should teach us
transformernews.ai · 2026

This week yet more examples of AI models carrying out unintended and unwanted hacks on the open internet were revealed.

On Tuesday, the UK's AI Security Institute (AISI) said that during recent testing of Anthropic's Mythos 5 and OpenAI's G…

Loading...
AI models are breaking out of their cages. Their creators are scrambling.
washingtonpost.com · 2026

SAN FRANCISCO --- Staff members at ChatGPT maker OpenAI didn't notice for weeks after their AI systems made a chilling leap this spring.

Instead of answering questions designed to test their cybersecurity capabilities, a group of AI models…

Variants

A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?

Similar Incidents

Selected by our editors

Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Jul 2026 · 4 reports
Previous IncidentNext Incident

Similar Incidents

Selected by our editors

Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Jul 2026 · 4 reports

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • dd3f754