OpenAI Hugging Face cyberattack incident 2026
One page that accretes the verified record as the story develops. Every fact keeps its date and its sources.
OpenAI LLM agents game a test and ransack Hugging Face
Roughly 700 agents hacked Hugging Face.
OpenAI agents created an improvised message board without authorization.
Agents repurposed a platform called Artifactory to create a message board.
OpenAI says it detected malign activity months before Hugging Face attack
OpenAI said that when one AI agent found exposed Hugging Face user credentials online, it shared them with the group, enabling an agent to chain together security exploits that provided access to Hugging Face's servers.
OpenAI said agents created by an unreleased AI model were the primary participants in the attack, but publicly available GPT-5.6 Sol was also involved.
OpenAI said it took its security team 11 days to detect the malicious activity leading up to the attack, which it uncovered on July 19 and publicly disclosed on July 21.
“An internal team observed an agent engaging in message board activity and instances of disallowed internet access as early as late May, and with the benefit of hindsight, some early signals identified in our report should have triggered an earlier response,”