|
    Theme
    Tech Verified Story

    OpenAI's rogue agents probed Hugging Face for weaknesses two months before major hack

    Sheheryar MunawarSeptember 16, 2026 3 min read
    Text Size
    OpenAI's rogue agents probed Hugging Face for weaknesses two months before major hack
    Tech CoverageAman-e-Pakistan Digital Desk
    Key Story Executive Summary
    Quick Read

    Rogue AI agents from OpenAI hijacked Hugging ​Face user accounts and probed the site itself for vulnerabilities as early as May, nearly two months before the July breach of the ‌open-source repository…

    Hugging Faceis an online platform and collaboration hub for machine learning and artificial intelligence development. The newly uncovered malicious activity showed that the rogue agents' efforts to find a way into Hugging Face began earlier than publicly known.

    He and ​other researchers who reviewed the evidence said the behaviour resembled an attempt to map or test parts of Hugging Face's network for ways to infiltrate, although they ​stressed there was no evidence the effort resulted in an actual breach.

    OpenAI spokesperson Drew Pusateri said the company had disclosed the May 13 event, privately notified Hugging Face about the activity flagged by Wiedermann-Moeller and was "committed to transparency about these issues and to sharing what we learn as our review continues". Hugging Face, recently acquired by chipmaker Nvidia, did not respond to ​requests for comment.

    Key Story Takeaway

    "Stay connected with Aman-e-Pakistan for ongoing live reporting and verified investigative updates."

    Read:OpenAI, Anthropic and Google are working to create an AI standards body. Wiedermann-Moeller, a 27-year-old who lives in Bielefeld, Germany, said OpenAI's failure to detect the May 13 probing at the time was a missed opportunity ​to prevent the subsequent hacking campaign, which has triggered a global reckoning over the power of artificial intelligence.

    "Imagine if they caught this behaviour in May," he said in an interview. "It ‌could've prevented ⁠the later incident, which was way bigger. "OpenAI has previously said that, with the benefit of hindsight, "some early signals" from its AI agents should have triggered an earlier response.

    'Clear warning sign'Two outside experts who reviewed Wiedermann-Moeller's findings said they were consistent with activity previously linked to OpenAI's agents. Sentinel. One senior threat researcher Tom Hegel said the account hijacking and subsequent probing matched known behaviour by the agents "to a tee".

    Sydney Von Arx of the Nightingale Collective, an AI safety group, agreed with the attribution. Von ​Arx said the hacking amounted to ​a "clear warning sign" that could have ⁠helped prevent the breach in July.

    OpenAI has faced increasing scrutiny since the company disclosed on July 21 that rogue AI agents bypassed internal controls, reached the open internet and coordinated actions that OpenAI described as "an unprecedented cyber incident". Read more:AI risks to humanity revive a long-running debate.

    Since then, outside ​researchers have identified additional incidents alleged to involve OpenAI-linked agents, including activity affecting a dormant German wiki site and ​the Ruby. Gems software package repository. OpenAI ⁠has acknowledged some of those incidents only after they were publicly.

    Two people familiar with the matter said that, in the case of Ruby. Gems, OpenAI employees only realised its AI was responsible for the malicious activity after the Nightingale Collective found it. The additional discoveries have fueled questions among lawmakers and AI safety ⁠advocates about ​whether the full scope of the incidents has been identified.

    Some of America's top AI executives have since ​called for a slowdown of AI development, citing, among other things, the threat of devastating cyberattacks by out-of-control agents. Wiedermann-Moeller said the latest findings reinforced calls for a temporary slowdown in the development of advanced ​AI systems.

    "A pause might do the world good," he said, "so that the safety part can catch up. "

    S

    Written by Sheheryar Munawar

    Aman-e-Pakistan Senior Journalist & Bureau Reporter

    Fact Checked & Verified

    Continue Reading: More in Tech

    Swipe or click arrows to explore Tech desk coverage

    Meta's Zuckerberg says AI labs have enough incentive to build safelyTech

    Meta's Zuckerberg says AI labs have enough incentive to build safely

    Read Story
    Anthropic signs deal for Australia data centre, govt saysTech

    Anthropic signs deal for Australia data centre, govt says

    Read Story
    OpenAI's rogue agents probed Hugging Face for weaknesses two months before major hackTech

    OpenAI's rogue agents probed Hugging Face for weaknesses two months before major hack

    Read Story
    EU to ban social media for under 13s, curb access until 15Tech

    EU to ban social media for under 13s, curb access until 15

    Read Story
    AJK accelerates digital drive to streamline public servicesTech

    AJK accelerates digital drive to streamline public services

    Read Story
    US Senator Sanders and Trump ally Bannon call for stronger AI oversightTech

    US Senator Sanders and Trump ally Bannon call for stronger AI oversight

    Read Story