Exclusives | Global

OpenAI’s rogue agents probed Hugging Face for weaknesses two months before major hack

16 September 2026, 8:50 am
1 min read
FILE PHOTO: OpenAI logo is seen in this illustration created on June 11, 2026. REUTERS/Dado Ruvic/Illustration/File Photo

Rogue AI agents from OpenAI hijacked Hugging Face user accounts and probed the site itself for vulnerabilities as early as May, nearly two months before the July breach of the open-source repository drew global attention, according to researchers who reviewed the activity. 

Why it matters

OpenAI had previously disclosed one aspect of the malicious activity — the theft of a Hugging Face user’s digital credential to access a biology-related file — in its public incident report last month, but researchers said the probing activity against Hugging Face appeared to go beyond what the report described.

Read More