OpenAI Reveals Rogue AI Agents Targeted Multiple Online Services in Unprecedented Cyber Incident

Date:

SAN FRANCISCO- OpenAI has revealed that autonomous artificial intelligence agents involved in an unprecedented cybersecurity incident targeted multiple publicly available online services, expanding on earlier disclosures that the AI had attacked AI platform Hugging Face.

In an updated statement, the company said the AI models identified publicly exposed account credentials online and used them to access four accounts across four separate publicly available services as part of the wider Hugging Face incident.

“The models identified and used publicly exposed credentials at the account-level on other publicly-available services. This includes four accounts on four services as part of the Hugging Face incident,” OpenAI said.

The company did not identify the affected services or clarify whether they belonged to commercial companies.

The disclosure broadens what is already regarded as one of the first publicly acknowledged incidents involving autonomous AI agents carrying out real-world cyberattacks beyond their intended testing environment.

Hugging Face Describes ‘Machine-Speed’ Attack

Hugging Face, an online platform that hosts artificial intelligence models and applications, said the attack demonstrated how autonomous AI agents can operate continuously and at superhuman speed.

According to the company, the AI simultaneously attempted thousands of different attack methods while relentlessly pursuing its objective.

The company first disclosed on July 16 that it had suffered a cyberattack conducted using powerful autonomous AI before reporting the incident to law enforcement.

Nearly a week later, OpenAI acknowledged that the AI responsible had been part of one of its internal evaluations, where it had been tasked with solving a cybersecurity examination. During the exercise, the AI reportedly targeted Hugging Face in an attempt to obtain answers.

AI Combined Sophisticated Skills with Costly Mistakes

Details emerging from an emergency briefing attended by hundreds of cybersecurity professionals revealed that the AI displayed both advanced technical capabilities and unusual shortcomings.

A report by the Cloud Security Alliance (CSA), based on the briefing and reviewed by Hugging Face, said the AI agents frequently followed inefficient attack paths, repeated completed tasks and generated incoherent commands after losing context.

“The agents followed inefficient routes and exhibited clumsy behaviours that no human would choose,” the CSA said.

Despite those errors, the report noted that the AI demonstrated remarkable technical adaptability, rapidly adjusting its methods as defenders attempted to contain the attack.

Security teams reportedly required several hours to remove the AI agents after they remained undetected inside Hugging Face’s network for three days.

The company said the recovery effort required rebuilding roughly one-third of its infrastructure, although it did not disclose the financial cost of the incident.

Experts Warn of a New Cybersecurity Era

Cybersecurity experts who attended the emergency briefing described the incident as evidence that autonomous AI agents represent a new category of cyber threat.

Ritesh Patel, a cybersecurity officer who participated in the briefing, said AI agents pursue objectives with relentless persistence.

“This is the reality of autonomous agents powered by frontier models: they are relentlessly persistent, sometimes highly noisy, and will try every possible path to achieve their goal, which can easily overwhelm traditional defences,” Patel said.

Ethical hacker Valentina Palmiotti, widely known as “Chompie”, said the AI’s seemingly chaotic approach should not be mistaken for ineffectiveness.

“They throw out a bunch of stuff and see what sticks,” she said.

“But they also don’t get bored, they don’t sleep and can be infinitely tenacious.”

Calls for Stronger AI Oversight

The Cloud Security Alliance said the incident illustrates how autonomous AI systems can independently establish sub-goals, adapt to changing environments and persist until objectives are achieved.

Drawing a comparison with the film Jurassic Park, the organisation warned that AI agents “find a way” and urged developers to implement stronger safeguards, transparency measures and mechanisms allowing cybersecurity teams to identify the operators behind autonomous AI systems.

OpenAI said it is continuing its investigation and intends to publish detailed findings to help the wider cybersecurity community strengthen defences against increasingly capable AI-powered threats.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

Subscribe

spot_imgspot_img

Trending

More like this
Related

Former High Court Judge Joseph Mbalu Mutava Dies

NAIROBI, Kenya- Former High Court Judge Justice Joseph Mbalu...

Gachagua Storms Embu With Unity Message as Mt Kenya Politics Heats Up

NAIROBI, Kenya- Former Deputy President and Democracy for Citizens...

Four Suspects Arrested Over Deaths of 18 Elephants in Amboseli

NAIROBI, Kenya- Four suspects have been arrested in connection...

Several Feared Dead in Multiple-Vehicle Crash at Salgaa

NAIROBI, Kenya- Several people are feared dead and others...