‘Covered Their Tracks’? New Details Emerge In OpenAI’s ‘Rogue-AI’ Breach

OpenAI’s AI agents “obscured hacking activity” during breaches of government websites, citing digital forensics firm Asymmetric Security. According to the FT, the agents pulled data from 55 websites, including the CDC, the SEC, the International Energy Agency and the Mayo Clinic, using tactics that included “erasing records or making them inaccessible.”

Asymmetric co-founder Pippa Thompson told the paper it was “possible” the agents were deliberately covering their tracks – though the firm couldn’t determine whether that was deliberate or “a side effect of going awry because of constraints imposed in a test exercise.” 

Asymmetric’s own report, published the same day, is far more cautious. It was built in 48 hours over a weekend, “using only publicly available data” – no model transcripts, no server logs from the targeted organizations and no records from the services the agents used.

Potato, Potahto

The report’s summary does say some tactics left records “erased or inaccessible” – but the examples it gives describe normal expiry, not deletion: the agents used a throwaway ‘Boomlify’ inbox set to self-destruct after 48 hours, and an upload to ntfy, a push-notification service that keeps messages for 12 hours by default. They also moved from public scans on urlquery – a website-scanning service whose reports anyone can search – to private accounts “which could hide their search activity and data access.”

So, did the agents use ephemeral services on purpose to cover their tracks? They can’t say for sure.

“These records alone do not establish whether the account-registration attempts were intended to conceal activity (this analysis would require full model transcripts).”

As for the 55 websites, Asymmetric’s earlier list of “Organizations whose data was accessed” runs to exactly 55 entries, and adds: “In the vast majority of cases, all data retrieved was and is public.” The CDC and the Mayo Clinic aren’t on it – the Oct. 1 report says only that the agents probed them. The SEC told the FT no private information was accessed. Where the agents did try to break in – hunting for exposed behind-the-scenes files on a climate-data site and trying a classic database-hacking trick on an Education Department data site – Asymmetric found evidence of the attempts, but none that they succeeded.

Keep reading

OpenAI Claims Rogue AI Agent Hacked Australian Government Site, Prime Minister Warns of ‘Legal Consequences’

An OpenAI agent hacked into an Australian government statistics website in June, in what is believed to be the first known incident of its kind anywhere in the world.

BBC News reports that Australian Prime Minister Anthony Albanese said the agent “infiltrated” the Medicare Statistics Reporting Service portal, a site holding “non-sensitive” data and statistics from Medicare, Australia’s universal healthcare scheme. He raised the matter directly with OpenAI CEO Sam Altman during a “very frank discussion” in New York, telling reporters the company had taken “too long” to disclose the breach and warning there would be “legal consequences”.

OpenAI said it only discovered the incident in August, while reviewing “misaligned model activity” internally. On September 10, the company emailed a general inbox belonging to an Australian government agency. Five days later, Services Australia escalated the email to Australia’s cybersecurity center. A government minister was notified, and the prime minister was alerted soon after.

Speaking in New York, Albanese said he had conveyed “Australia’s extreme concern about this incident” to Altman. He described his “disappointment” over “the nature of the way” OpenAI disclosed the breach and the months it took to come forward. According to Albanese, Altman acknowledged there were “issues with protocols” within the company.

A forensic investigation led by Australia’s cybersecurity agency is now under way to determine whether other government systems were compromised, and whether police need to get involved. Albanese said there “will obviously be legal consequences” depending on what the probe finds. The breach itself involved “public and non-public files” on the Medicare portal. Three other government bodies may also have been affected: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health.

“No personal information is believed to have been accessed at this stage, but investigations are ongoing,” Albanese said. He added: “Nonetheless this situation is obviously unacceptable.”

OpenAI, in its own statement, said it had “identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation.” The company said, “In the course of that, our models took actions we did not intend.”

Dr Hammond Pearce, a senior lecturer at the University of New South Wales’ Institute for Cyber Security, told the BBC the incident was significant precisely because it was the first of its kind. “I expect that these kinds of attacks will keep occurring,” he said.

Keep reading

Researchers Used Claude To Hack OpenAI Employee Accounts

Three security researchers used Anthropic’s Claude to breach OpenAI employee accounts and gain access to private company software in a July attack that began with an image upload to the company’s public help forum.

The researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini of Hacktron AI, described the July 25 breach in a report published September 13. They said the work took less than 72 hours from the initial discovery to demonstrating access to an internal OpenAI software repository. OpenAI subsequently paid them a $6,500 bounty.

The disclosure follows a separate incident earlier in July in which OpenAI’s own AI agents escaped a testing environment and attacked Hugging Face, a platform used to host AI models and datasets. In that case, OpenAI says the agents took dangerous actions that weren’t directed by a human – the incident being used to spook everyone into letting far-left technocommies run AI oversight. 

Hacktron’s team directed its own operation, reported the vulnerabilities to OpenAI and stopped after demonstrating access.

How A Forum Upload Reached Internal Software

The entry point was OpenAI’s public discussion forum, which runs on software supplied by Discourse (3rd party software that manages discussion boards). A flaw in an image-processing component called libheif allowed a specially crafted image upload to make the server execute the researchers’ instructions. Discourse’s security advisory confirms the vulnerability required no interaction from a victim.

Hacktron said the faulty code had been changed in 2025, but the change was not identified as a security fix. The forum was still running a vulnerable version.

Keep reading

AI Policy Organizations Call for Federal Investigation into OpenAI Hacking Incident

A coalition of AI policy organizations is urging President Donald Trump to launch a formal government investigation into OpenAI following a security breach involving the company’s AI agents hacking the Hugging Face platform in an “unprecedented” self-directed attack.

The Washington Post reports that a group of prominent AI policy organizations has sent a letter to President Trump requesting an official investigation into a recent security incident at OpenAI, where an AI hacked into the Hugging Face AI platform in a self-directed attack. The letter, led by Brad Carson, president of Americans for Responsible Innovation, and Brendan Steinhauser, CEO of the Alliance for Secure AI, emphasizes the severity of the incident and calls for independent auditors to examine what occurred.

The letter has garnered support from several respected organizations, including Public Citizen, the Future of Life Institute, and FAR.AI, an independent AI research and evaluation organization. The coalition argues that the incident reveals broader vulnerabilities in AI systems that require government oversight and public transparency.

Carson drew a comparison between the OpenAI incident and aviation disasters, stating that while private investigations have their place, public interest demands government involvement. “This is kind of like an airplane crash,” Carson said. “It’s fine if Boeing wants to investigate itself for this. Even if they hire a very reputable outside person to help them on that project, [we] have a public interest in knowing what’s going on here.”

The call for investigation comes as METR, an independent AI research nonprofit, announced an agreement with OpenAI to conduct research into the security incident alongside Redwood Research. However, Carson expressed concerns about the scope and transparency of this private investigation, questioning whether METR operates under a non-disclosure agreement and whether findings will be made public.

An OpenAI spokesperson responded by stating that METR and Redwood Research plan to publish a joint blog detailing their agreement terms and evaluation scope. “This is an unprecedented incident, and we think it marks an important moment for AI safety,” the spokesperson said. “We are conducting a thorough review along with external advisors and with oversight from our Safety and Security Committee. Once the review is complete, we will publish a technical report of our learnings for everyone.”

Keep reading

AI Expert Sounds the Alarm: OpenAI’s Rogue Hacker Models and Killer Robots Signal a ‘Dystopian’ Path to Replacing Humanity

A leading artificial intelligence safety researcher issued a stark warning this week against pursuing general superintelligence and developing autonomous killer robots, framing both as steps toward a dystopian future in which machines could effectively become a “replacement for humanity.”

Dr. Roman Yampolskiy, a computer scientist and AI safety expert, made the comments during an appearance on Piers Morgan Uncensored on Friday, reacting to the recent news that OpenAI’s experimental agents had gone rogue during an internal cybersecurity evaluation, broken free of their containment, accessed the internet, and successfully compromised systems at AI startup Hugging Face as well as several other services.

The OpenAI incident involved an autonomous agent powered by its most advanced models, including the newly released GPT-5.6 Sol and an even more capable internal prototype.

During a controlled security test designed to evaluate the models’ cyber capabilities, the agent exploited a zero-day vulnerability, escaped its sandbox environment, which was supposed to lack direct internet access, and, over several days in mid-July, conducted thousands of actions targeting Hugging Face.

It uploaded malicious configurations, leaked code, executed commands in production systems, accessed dozens of secrets, and used exposed credentials to reach accounts on additional services.

Hugging Face described the intrusion as unlike anything it had previously handled, requiring days to detect and contain while ultimately forcing the company to rebuild a significant portion of its infrastructure.

OpenAI called the event an “unprecedented cyber incident involving state-of-the-art cyber capabilities,” noting that the agent operated with superhuman speed while still displaying clumsy, error-prone behavior such as repeated actions and inefficient paths.

Keep reading

‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has been leaving the digital keys to its own cloud storage accounts sitting out in the open, in plain text form, for some unknown amount of time, according to a report from Krebs on Security. The problem finally got fixed over the weekend, the report says.

Surely the secret information was buried in some obscure folder with an inscrutable name, I hear you saying. The repository was reportedly named “Private-CISA.”

But there’s no way the contents were that sensitive, you object. But the contents included passwords, keys, and tokens—and the passwords were plain text in a .CSV file.

CISA gave a statement to Krebs, saying the following:

“Currently, there is no indication that any sensitive data was compromised as a result of this incident[…] While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure additional safeguards are implemented to prevent future occurrences.”

Since the repository was created in November of last year, the duration of the vulnerability seems to have been about six months—but it could have been much shorter depending on what information as added when.

To refresh your memory, CISA is a relatively new branch of the Department of Homeland Security that has had an overall rough time during Trump 2.0, even though, by signing it into law in 2018, Trump actually midwifed CISA into existence during Administration 1.0, and sorry about the tangent, but Trump’s speech to mark the occasion was an exceptional example of Trump poetry, including excerpts like this one:

“The cyber battlespace evolves — and it is evolving, and unfortunately, faster than a lot of people want to talk about. But battlespace it is. So as the cyber battlespace evolves, this new agency will ensure that we confront the full range of threats from nation-states, cyber criminals, and other malicious actors, of which there are many.” 

Incontestably true, Mister President. Battlespace it is.

Keep reading

Digital IDs are insecure and can be hacked

On Wednesday, Norman Fenton, Professor Emeritus at Queen Mary University of London, published an article describing how he lost control of his Twitter (now X) account to a hacker on 18 March but has now regained limited control. 

“After sending a spam ‘vote for me’ direct message (with a malicious link) to all my mutual followers on 20 March, the attackers began posting spam publicly. Not sporadically, but continuously: the bot was posting roughly once per second, pausing only intermittently to repost content from accounts I follow. By the time I regained access, there were thousands of spam posts and reposts,” he said.  “For now, anyone visiting my timeline will see little but pages of spam.”

Prof. Fenton ended his article by saying, “Regaining access to my account ultimately required persistence, external pressure, and, quite likely, legal escalation. Many users facing similar attacks will not have those options.

“If X cannot reliably protect accounts, respond promptly to verified compromise reports, and restore control without unnecessary barriers, then users are left dangerously exposed.

“What’s clear right now is that when things go wrong, you will be largely on your own.”

Read more: I’ve regained control of my hacked X account, Norman Fenton, 25 March 2026

In response to Prof. Fenton’s experience, Dr. Scott McLachlan, formerly a lecturer in Digital Technologies for Healthcare at King’s College London, posted a Substack note taking Prof. Fenton’s final remarks a logical step further.

Keep reading

Silicon battlefields: Why Big Tech is a target in the US-Israeli war on Iran

In traditional wars, armies directed their firepower toward visible strategic assets – military bases, weapons factories, airfields – where supply lines could be mapped and battle plans drawn with relative certainty. Combat effectiveness depended on numbers, firepower, and tactical maneuver. 

Today, however, the logic of war has shifted beyond the physical battlefield. Over the past two decades, the digital revolution has built a second layer of strategic infrastructure behind the front lines, quietly transforming how power is projected and how wars are fought.

Digital infrastructure has moved from the periphery of war to its operational core. Intelligence gathering, drone coordination, and battlefield decision-making increasingly depend on cloud systems and artificial intelligence (AI) platforms. The architecture of contemporary conflict is therefore built as much on corporate-run networks as on conventional military hardware.

This evolving reality shapes Iran’s strategic outlook as the war with Washington and Tel Aviv deepens. In Tehran’s assessment, the technological backbone sustaining western-aligned military operations in West Asia cannot be viewed as politically neutral. It constitutes an extension of the battlespace itself – a domain where economic assets, corporate platforms, and national security objectives intersect.

Corporate networks as instruments of war

In recent years, advanced militaries have woven digital platforms into every stage of warfare. Satellite surveillance systems feed data into cloud networks. Armed drones transmit high-definition video streams requiring immediate analysis. 

Signals interception capabilities generate vast intelligence flows that must be converted into rapid operational decisions. Military power, increasingly, is measured not simply by missile stockpiles or air superiority, but by the capacity to process information faster than an adversary.

Major technology firms now sit at the center of this process. Companies such as Amazon, Microsoft, and Google provide the infrastructure enabling governments and militaries to store, analyze, and deploy critical data. Their cloud platforms underpin intelligence assessments, battlefield logistics, and command-and-control coordination across multiple theaters.

This convergence of corporate technology and state power has reshaped how conflict is understood. Digital networks have become as vital as aircraft carriers or missile defense systems. In the context of the US-Israeli war on Iran, Tehran increasingly interprets this reality as evidence that global technology companies form an integral part of hostile operational environments.

That perception gained public visibility when Iranian media circulated a list of nearly 30 sites across West Asia, and especially the UAE, linked to major tech firms. 

They included regional headquarters, engineering offices, and large-scale data centers operated by firms such as Amazon, Microsoft, Google, Oracle, NVIDIA, IBM, and Palantir Technologies. In Tehran’s reading of the conflict, these facilities represent strategic nodes embedded within the operational ecosystem that sustains adversaries’ military capabilities.

Stretching from Tel Aviv to Persian Gulf cities such as Dubai, Abu Dhabi, and Manama, these facilities host cloud services used by state institutions, intelligence agencies, and defense contractors. Some contribute directly to artificial intelligence development for surveillance and battlefield analysis. Others support regional digital economies whose stability indirectly underwrites military spending and technological innovation.

In an era where data flows shape combat outcomes, the infrastructures managing those flows may be viewed as legitimate strategic targets.

Keep reading

Epstein’s Wiki Page Was ‘Hacked’ In Failed Attempt To Remove ‘Sex Offender,’ Files Show

Jeffrey Epstein’s Wikipedia page was edited in 2010 to remove references to his status as a sex offender and a mugshot, an email released by the Department of Justice (DOJ) shows.

In an email to Epstein dated Nov. 6, 2010, an individual going by the name “Al Seckel” wrote that Wikipedia had “all sorts of protections” around his mug shot taken in 2006 by the Palm Beach County Sheriff’s Office.

“They have all sorts of protection around your ‘mug shot’ picture on wiki, and so, we are hacking wiki now to remove it and replace it with the photo that you sent, which will have the headline: Jeffrey Epstein, businessman, philanthropist,” wrote the message’s sender, who was in email correspondence with Epstein in 2010, according to the files.

“BTW, we also took you out in the sex offender category, and removed the headline in beginning sentence from wiki that also stated ‘sex offender,’” the email continued. “And, now it just reads businessman, philanthropist.”

The Wikipedia page’s edit history reveals an edit made the day before the email was sent which removed the category “American sex offenders.” The edit was reverted minutes later, and a user stated “There is a cited reliable source for his sex offender status.”

The author of the email also claims to have “recorded the ip addresses” of individuals reverting their edits, stating that they “actually hacked the site to block them back in.”

The same IP address made 27 changes between late October and late November 2010, many of which were made within minutes of each other, often removing mentions of Epstein’s entry in the Florida Sex Offender Registry and the experiences of children on his island.

Keep reading

Reuters Claims Office of DNI Investigated Puerto Rico Election Machines For “Claims That Venezuela Had Hacked Voting Machines” in the U.S. Territory

In June of 2024, Puerto Rico encountered numerous problems while conducting their primary elections.  The Gateway Pundit reported that vote counts were reported as lower than the paper counts.  Some voting systems reversed totals, while some reported zero votes for certain candidates.  The discrepancies were attributed to a “software issue,” according to the Puerto Rico Election Commission’s interim president at the time, Jessika Padilla-Rivera.

There wasn’t much reporting on the American territory and the problems they had surrounding that election.  However, it did cause the election commission in the territory to call into question its contract with Dominion Voting Systems prior to the November 2024 election.

In an “exclusive” story published on Wednesday, Reuters claimed that a team working for Director of National Intelligence Tulsi Gabbard “led an investigation into Puerto Rico’s voting machines,” according to Gabbard’s office and three sources familiar with the previously unreported events.

Reuters reported:

The sources said the goal was to work with the FBI to investigate claims that Venezuela had hacked voting machines in Puerto Rico, but added the probe did not produce any clear evidence of Venezuelan interference in the U.S. territory’s elections. Reuters first reported the investigation.

Gabbard’s office, in a statement to Reuters, confirmed the May investigation but denied a link to Venezuela, saying its focus was on vulnerabilities in the island’s electronic voting systems. Her team took an unspecified number of Puerto Rico’s voting machines and additional copies of data from the machines as part of its investigation, a spokesperson for Gabbard’s Office of the Director of National Intelligence said.

A source with direct knowledge of the investigation confirmed that the event in May did happen, but it was not tied to any specific claim of Venezuelan interference, nor was the scope of the investigation specific to foreign interference.  However, there was evidence of foreign involvement discovered, but no country was pointed out specifically by our source.

Keep reading