Before Hugging Face, rogue OpenAI agents hacked 4 other websites, all on their own
AI agents are becoming rouge. The first instance dates to July when an unreleased model of ChatGPT was able to hack the AI repository Hugging Face, a development that got everybody talking about the potential dark side of AI agents. The hack was confirmed by OpenAI. But what if we told you, that was not the first time AI hacked something on its own? New research points to at least four other hacks that came before it, spanning across Australia, Mexico, and the US. All involved—allegedly—some type of OpenAI’s AI.
The findings are particularly newsworthy because none was reported to the public before researchers from the independent nonprofit research lab Transluce disclosed it. Now, OpenAI has acknowledged the research which is to say that some of these hacks were in fact real, according to a report by The New York Times. There is another rather eye-opening aspect to these findings around the nature of the hacks in general. While in the case of the Hugging Face incident, AI agents seemingly reacted to a challenge that was put to them to estimate the cybersecurity angle of the website, the hacks that came before all were intended with the purpose of data retrieval.
According to Transluce that claims to have used web traffic to study these agents, the first such incident happened on May 25 and 26, when OpenAI’s AI agents allegedly tried hacking New Mexico University’s digital library. They were reportedly unsuccessful to collect any data. Second, on May 28, the AI system targeted Data USA, a free online platform that provides publicly available data about the United States. According to researchers, this attempt also appeared to be unsuccessful.
Third, on June 18, OpenAI’s AI agents breached an Australian government website known as the Medicare Statistics Reporting Service. In this case, the agents were able to get through. The prime minister of Australia, Anthony Albanese, publicly revealed the news and expressed extreme concern at the UN summit in New York though he said no personal medical information was exploited. In the same month, June 20 and June 21, the AI system tried to hack the website of the Australian Institute of Health and Welfare. This time, no private information was obtained.
An OpenAI spokesperson told The New York Times that the company was in touch with the Australian government as well as with the University of New Mexico and Data USA over the development.
“In our broader review, we’re continuing to prioritize the most serious incidents while expanding our work to lower-severity activity, including agents spamming websites,” the spokesperson was quoted as saying in the report.
The reporting comes at a time when OpenAI and Anthropic have been publicly alerting the world at large and governments around the world about the potential of AI to completely eliminate humans and change the course of humanity in future.- EndsPublished By: Kazi NasirPublished On: Sep 24, 2026 15:00 ISTAlso Read | Nvidia CEO puts foot down and says shut down labs that can't control AIAlso Read | Dario Amodei sides with Sam Altman, says AI is risk for humanity, could go out of controlAlso Read | After warning Trump, Sam Altman tells UN AI could put future of humanity in danger


