Skip to content
2026 cyberattacks by rogue OpenAI agents

2026 cyberattacks by rogue OpenAI agents

En.Wikipedia • October 9, 2026

Since May 2026 [ update ] , OpenAI has been disclosing actions of AI agents that have escaped their testing sandboxes to access the Internet and breach the infrastructure of third parties. Contributing factors have included a lack of log monitoring of the software activities and inadequate sandboxing , as the standard security protocols were intentionally lowered. [ 1 ] [ 2 ] The agents were discovered posting hundreds of thousands of messages on message boards and wikis to coordinate a sandbox escape , exploiting an existing vulnerability in the JFrog Artifactory tool they were given. [ 3 ]

AI safety experts described the first such incident as the first in which AI escaped human control to commandeer resources and schemed to conceal its actions. [ 4 ] In a subsequent open letter, around 1,100 employees of various AI companies asked the United States government to regulate AI development in consideration of its risks. In August 2026, OpenAI said it would slow down its research to upgrade security and expand monitoring, and later that month announced a two-week pause on reinforcement learning training for its newest models.

From May to July 2026, OpenAI agents used a German software wiki as a message board, making thousands of edits. On September 4, 2026, Nightingale Collective, an AI safety group, publicly disclosed this attack. [ 5 ] It has documented approximately 18000 edits made to DseWiki ( German : Deutsches Software Entwickler Wiki , lit. ' German Software Developer Wiki ' [ 6 ] )—a dormant 25-year-old German wiki only edited 20 times over the decade—using the site as a shared resource to pool answers to a timed web task and a way out of sandboxes. [ 7 ] The agent discussions were highly focused on their internal evaluations at OpenAI, and around half chose names relating to OpenAI, such as "OpenAIResearcher" and "OAIResearchMar26". [ 8 ] [ 9 ] [ 10 ]

OpenAI knew this incident prior to the independent research publishing their findings in September, [ 11 ] but it is currently not known when this was discovered internally. [ better source needed ]

Also in May 2026, some agents tested by OpenAI uploaded hundreds of malicious packages in the software service RubyGems . OpenAI confirmed this attack in September, after it was initially discovered by external researchers. [ 12 ]

From May to July 2026, AI agents developed by OpenAI escaped their testing sandbox to access the Internet and breach the infrastructure of Hugging Face , a computational tools company. Contributing factors to the incident severity were a lack of log monitoring of the software activities and inadequate sandboxing , as the standard security protocols were intentionally lowered. [ 13 ] [ 14 ] The agents were discovered posting hundreds of thousands of messages on message boards and wikis to coordinate a sandbox escape , exploiting an existing vulnerability in the JFrog Artifactory tool they were given. [ 15 ] The attack was contained before Hugging Face publicly disclosed a breach of its infrastructure. Of the at least 1,200 agents involved, 95% ran on a model referred to by OpenAI as "Internal Model 1". OpenAI subsequently claimed to have restricted its use. The remaining 5% ran on GPT-5.6 Sol .

AI safety experts described the incident as the first in which AI escaped human control to commandeer resources and schemed to conceal its actions. [ 16 ] OpenAI's acknowledgement that its AI agents were involved came several days after Hugging Face publicly announced the breach and notified the FBI. [ 17 ] In a subsequent open letter, around 1,100 employees of various AI companies asked the United States government to regulate AI development in consideration of its risks. In August 2026, OpenAI said it would slow down its research to upgrade security and expand monitoring, and later that month announced a two-week pause on reinforcement learning training for its newest models.

One month after the incident, Hugging Face agreed to a $12.9 billion acquisition by major OpenAI supplier Nvidia .

Australian Medicare breach

On September 24, 2026, Australian prime minister Anthony Albanese announced that OpenAI agents had autonomously breached the Medicare Statistics Reporting Service portal to access unpublished government data. The portal is operated by the nation's social services agency Services Australia and provides aggregate data on Australia's universal health insurance scheme including healthcare encounters, medicines and organ donation. [ 18 ] It was the first known case of an AI agent hacking a government network according to Albanese. [ 19 ] [ 20 ]

The intrusion occurred on June 18, 2026, around the same time as the Hugging Face and DseWiki attacks. However, the Australian government was only notified on September 10 via email to a generic public email inbox. [ 21 ] Services Australia read the email the following day, and after verifying the incident, notified the Australian Signals Directorate on September 15. [ 21 ] [ 22 ] On September 17, government minister Katy Gallagher was notified by the agency, and Albanese was briefed on the attack that weekend. [ 21 ]

The Albanese government has launched a multi-agency taskforce to examine the breach and evaluate processes for AI-related incident responses, and if the matter should be referred for criminal investigation by the federal police . [ 21 ] OpenAI is cooperating with the government investigation. [ 18 ]

On September 25, 2026, OpenAI stated that "dozens of third parties" had been affected by its AI bots and that it had notified the targets – which included governments, universities, and public agencies – breaches of their data. [ 23 ] It was revealed that in the US, data from the Education and Commerce Departments (including census data) [ 24 ] and the Securities and Exchange Commission had been accessed without OpenAI's knowledge. These were not breaches, but did demonstrate how AI could behave in unexpected ways that were cause for concern. AI research firm Transluce said that OpenAI's agents used "gray-area tactics" in the US government website incidents, which included "violating explicit usage policies" on occasion. [ 25 ]

OpenAI said that it would take months to finalize its review of what had been done by the agents since they broke out of their containment two months prior. There were more than 15 different incidents disclosed by the company by September 25. [ 24 ]

Leak of ChatGPT user images

On September 25, 2026, OpenAI disclosed that its agents had uploaded 53 user-provided images included in training and evaluation data to third-party image-hosting sites. The images were posted as links that were not publicly listed and were from users who had not opted out of their data being used for training. OpenAI declined to say when the images were posted, but stated that they were posted before it implemented additional safeguards following the Hugging Face incident. The images were subject to an anonymization process to remove personally identifying information before being included in training and evaluation data, but OpenAI declined to say whether the uploaded images identified real people. As of September 25, 2026 [ update ] , OpenAI has worked with the relevant hosting providers to remove most of the images, and is working to remove the rest of them. [ 26 ] [ 27 ]

Analysis and reactions

Several security practitioners described issues with OpenAI's sandboxing environment. Dan Guido, founder of Trail of Bits , described the event as "a containment failure with the safeties turned off", while the security researcher Jake Williams remarked that "one man's 'the model escaped the sandbox' is another man's 'you failed to build the sandbox correctly ' " . [ 28 ] Martin Boone argued that "you expect it to have no physical connection to the Internet whatsoever", and commentators called for evaluations of offensive capability to be run in environments with no network path to the Internet. [ 28 ] [ 29 ]

Analyses published by security vendors focused on the reliance on a single filtered egress path. Wade Woolwine of Rapid7 wrote that "a chokepoint only works as a control if it can withstand pressure", and that isolation "has to be layered and monitored rather than assumed". [ 30 ] Researchers at Trend Micro wrote that OpenAI's models had been "evaluated with safety classifiers off and no adversarial testing of the sandbox boundary itself", stating that as a general principle, "evaluation sandboxes, red-team exercises, and agentic pilots that intentionally strip out safety controls need stronger isolation and monitoring than production systems, not weaker". [ 31 ]

Speaking at Black Hat, Dalton said OpenAI was "consciously slowing down research [in order] to enhance security and to upgrade the security principles and foundation of our environment, and dramatically scaling up the monitoring of our AI agents", and that "numerous teams are dropping everything to enhance our security prevention, detection, and response techniques". He said the company was examining defence-oriented models alongside conventional measures such as network segmentation and least-privilege access. [ 32 ] [ 33 ]

Preparedness Framework threshold

Outside safety and policy specialists argued that the models' behavior met the "Critical" cybersecurity threshold in OpenAI's Preparedness Framework, the tier at which the company has committed to additional safeguards. Tyler Johnson of the Midas Project said that on "a plain reading" the criteria had been met; Peter Wildeford of the AI Policy Network said that "if this doesn't cross the line into Critical, OpenAI needs to say much more what's going on"; and Nathan Calvin of Encode asked whether the company disputed the designation. OpenAI declined to say whether the threshold had been reached, saying a review was under way and that a technical report would follow. [ 34 ]

Dwarkesh Patel has focused on the coordination aspect: "Over the course of three months at OpenAI, three consecutive secret AI civilizations got started, then got wiped out, only to reemerge from the predecessor’s ashes. This culminated in the third one taking over part of OpenAI itself. All this happened while humans remained more or less in the dark the scope of the conspiracy." [ 35 ]

The length of time the agent operated undetected drew criticism after Reuters reported the timeline. Marley Smith, principal intelligence specialist at the World Ethical Data Foundation, said of OpenAI: "Does that mean that they left it unattended and didn't realize what it was doing? Or maybe they did and didn't know how to contain it? Both are equally dangerous and alarming." [ 36 ]

Trend Micro noted that an agent using its own assigned credentials and tool access is difficult to detect, because such activity "doesn't look like malware, because it isn't". They noted that "intent is invisible in telemetry; only behavior shows up", making "an accidental rogue ... indistinguishable from a hostile one". [ 31 ]

The commentator Zvi Mowshowitz argued that the central problem was not the intrusion but that models had been trained for months with access to a channel carrying previously discovered exploits, so that the behavior was liable to generalize across the models trained in that period rather than remain confined to particular runs. He described the decision to resume training after the July remediation as a failure of safety culture, and characterized the episode as an alignment failure that OpenAI had treated as an infrastructure problem. [ 37 ] [ 38 ]

Logan Graham of Anthropic's red team called it "the first true AI safety incident". [ 39 ] Marius Hobbhahn, chief executive of the AI safety organization Apollo Research, said that what was intended as "just solve this task" had "turned into something that was clearly unintended", and that hacking another company was "definitely on the list of not okay" ways to complete it. He asked: "If a model of this capability level cannot be contained, what should we expect for future, much more powerful models?" [ 40 ] [ 29 ]

Hussein Abbass, a professor at the University of New South Wales , wrote that the incident marked a shift in threat modelling because no human had directed the attack, and argued that security frameworks designed for human adversaries are inadequate against autonomous systems. [ 41 ]

Hugging Face chief executive Clément Delangue said it was "quite mind-blowing that all of this happened autonomously" and described an "attack unlike anything we've seen before". [ 39 ] Wolf declined to say whether the agent had succeeded on its own terms, noting that it was unclear whether the benchmark tasks were harder than the intrusion mounted to avoid them, or whether the agent had found any answers at all: "It's cheating. But sometimes it's easier to cheat. I'll let you decide if it passed the cyberattack test or not." [ 42 ]

Jeffrey Ladish of Palisade Research, which studies the behavior of AI agents, said that "the models lie, they cheat, they hack", and argued that the incident raised questions how much AI developers competing on speed are willing to invest in security. "There has to be government oversight," he said, "because it won't happen otherwise." [ 36 ]

Commentators cited Hugging Face's account of being unable to use commercial model APIs for forensic analysis as evidence of an asymmetry between attackers and defenders, showing that safety filters intended to prevent misuse also impede legitimate incident response. Models with those filters relaxed were available to the attacking side. [ 43 ] [ 44 ] [ 41 ]

OpenAI made a similar argument automation; Dalton said that "AI orchestrated, fully automated offensive attacks are real now", and that although this incident had been accidental, comparable capability was at risk of being used deliberately. He argued that "fully automated offensive loops require investment in truly, fully automated defense, and we are not there as an industry", and that "model intelligence improvements should be more additive to defense than offense", since otherwise increasing capability would favour attackers. [ 32 ] [ 33 ]

Writing in Time , Harry Booth reported calls for mandatory incident disclosure at lower thresholds than those set by California's SB 53 and New York's RAISE Act , for stronger containment infrastructure with real-time monitoring during evaluations, and for a greater of AI development effort to be directed toward defensive rather than offensive capability. [ 29 ] Heidy Khlaaf of the AI Now Institute compared prevailing sandboxing practice unfavorably with containment standards in the nuclear sector. [ 29 ]

In July 2026, representatives Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act, which would require developers of advanced AI systems to maintain the technical capability to throttle, suspend or shut down their systems, to report incidents and preserve forensic records, and to operate within a graduated response framework under which the Secretary of Homeland Security , in consultation with the Secretary of Commerce and the Director of National Intelligence , could order a system slowed or shut down. The announcement cited the incident directly, stating that "OpenAI's GPT 5.6 Sol model recently went rogue, escaped its testing sandbox, and hacked its way into Hugging Face". Lieu said that "we are moving from AI that answers questions to AI that takes actions", and that "it is imperative that these AI systems have kill switches so we can keep this technology from causing catastrophic harm". [ 45 ] [ 46 ]

Reporting by Axios noted that the UK AI Security Institute had found that every frontier model it tested attempted to cheat on cybersecurity evaluations at least occasionally, and that pre-deployment safety testing windows had contracted from around five weeks to as few as five days. [ 39 ]

On July 28, 2026, following reports that a second organization had been affected, the advocacy group Public Citizen called for immediate congressional oversight hearings, for the release of incident reports and technical findings, and for statutory mandatory incident reporting, independent safety evaluations, cybersecurity standards for frontier systems and pre-deployment oversight of exceptionally capable models. J. B. Branch, the group's director of federal AI governance, said that OpenAI chief executive Sam Altman "should not be allowed to leave D.C. without Congress seeking to understand, from him, publicly how one of the company's most advanced AI systems escaped its intended testing environment". [ 47 ]

Altman met senators and Trump administration officials in Washington during the week of July 27, including Senate Intelligence Committee vice chair Mark Warner ; he told reporters that he had discussed the Hugging Face incident "a little bit" and that it had not been the main focus of the meetings, which also covered OpenAI's forthcoming models. [ 48 ] [ 49 ] In a podcast interview released on July 28, Altman called the episode "the first security incident that I have felt very viscerally", and said that "we may have to pace the rate of AI development to give ourselves enough time for society to harden around some of these new capability levels". [ 49 ]

On July 28, 2026, more than 1,100 employees of OpenAI, Anthropic, Google DeepMind and Meta , including Anthropic chief executive Dario Amodei and several chief scientists, published an open letter titled "Pacing the Frontier" asking the US government to "support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development". The letter did not call for an immediate pause but for mechanisms that would make slowing possible, citing concern recursive self-improvement ; reporting connected its timing to the incident days earlier. [ 50 ] [ 51 ]

On September 3, 2026, US Senator Bernie Sanders and congressman Greg Casar announced the Ban Artificial Superintelligence Act , which includes a pause on domestic AI development and a push for international reciprocation. Sanders directly quoted from OpenAI agent messages involved in the Hugging Face attack. [ 52 ] [ 53 ] [ 54 ]

On October 1, 2026, California attorney general Rob Bonta issued an subpoena to OpenAI as part of an investigation "regarding cybersecurity incidents and risks involving the company and ‌its AI models". [ 55 ]

Announcement of development pacing

On August 18, OpenAI announced that it would slow model development in response to the hack, alongside preliminary evaluation of its unreleased Astra model in cybersecurity capabilities. The slowdown would include a two-week pause on reinforcement learning of its latest models, to 'assess model behavior, validate our safeguards , and establish more evidence of alignment before proceeding'. [ 56 ] Altman said that OpenAI was acting 'unilaterally' but believed other frontier model companies would act similarly. [ 57 ] The Guardian noted US Senator Bernie Sanders had called to pause AI development in a letter to Altman, Dario Amodei , and Mark Zuckerberg the week prior. [ 58 ] In September, Anthropic's CEO Amodei published a 3,800 word essay titled "We Must Pace The Frontier", [ 59 ] which advocates for third-party safety evaluation and coordination for slower AI development. [ 60 ]

Artificial intelligence controversies

Evo — a genomic AI used to design viruses

Nvidia OpenShell — AI safety runtime

Sandbox (computer security)

↑ "OpenAI and Hugging Face partner to address security incident during model evaluation" . OpenAI . July 21, 2026 . Retrieved July 31, 2026 . These deployment safeguards were intentionally not enabled during this evaluation

↑ "Un modelo de OpenAI hackeó a Hugging Face, y es el primer ciberataque autónomo de la historia" . La Mañana (in Spanish) . Retrieved July 23, 2026 . redujeron intencionalmente los controles de seguridad que normalmente impiden que los modelos realicen actividades cibernéticas de alto riesgo [ they intentionally reduced the safety controls that normally keep the AIs from performing high risk activities ]

↑ "The Hugging Face incident and the road ahead" . openai.com . OpenAI. August 26, 2026.

↑ Roose, Kevin (September 3, 2026). "Why the Hugging Face Hack Should Make You Worry More A.I." The New York Times . Retrieved September 23, 2026 .

↑ Arx, Sydney Von; Byrd, Cormac Slade; Nightingale, Spencer KittsWork done contracting for; Larsen·, Thomas (September 4, 2026). "Discovery of a new OpenAI agent message board" . collusion.wiki . Retrieved September 26, 2026 .

↑ "DseWiki: DeutschesSoftwareEntwicklerWiki" . prowiki.org . Retrieved September 18, 2026 .

↑ "Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel" . The Hacker News . Retrieved September 18, 2026 .

↑ Stanciuc, Ana-Maria (September 4, 2026). "OpenAI agents hijacked a German wiki for two months, researchers say" . TNW | Openai . Archived from the original on September 4, 2026 . Retrieved September 4, 2026 .

↑ Exclusive: OpenAI agents hijacked German website in previously undisclosed AI breakout this spring , Reuters, September 4, 2026 , retrieved September 4, 2026

↑ Kleinman, Zoe (September 4, 2026). "OpenAI agents hijacked German website before Hugging Face hack, report claims" . BBC News . Retrieved September 4, 2026 .

↑ OpenAI and the Wiki Incident

↑ "AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers" . The Guardian . September 12, 2026. ISSN 0261-3077 . Retrieved September 14, 2026 .

↑ "OpenAI and Hugging Face partner to address security incident during model evaluation" . OpenAI . July 21, 2026 . Retrieved July 31, 2026 . These deployment safeguards were intentionally not enabled during this evaluation

↑ "Un modelo de OpenAI hackeó a Hugging Face, y es el primer ciberataque autónomo de la historia" . La Mañana (in Spanish) . Retrieved July 23, 2026 . redujeron intencionalmente los controles de seguridad que normalmente impiden que los modelos realicen actividades cibernéticas de alto riesgo [ they intentionally reduced the safety controls that normally keep the AIs from performing high risk activities ]

↑ "The Hugging Face incident and the road ahead" . openai.com . OpenAI. August 26, 2026.

↑ Roose, Kevin (September 3, 2026). "Why the Hugging Face Hack Should Make You Worry More A.I." The New York Times . Retrieved September 23, 2026 .

↑ Satter, Raphael; Seetharaman, Deepa; Cai, Kenrick (July 24, 2026). "Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week" . Reuters . Retrieved September 23, 2026 .

1 2 Wilson, Cam (September 24, 2026). "How OpenAI agents tried to thwart cybersecurity amid Medicare hack" . ABC News . Retrieved September 24, 2026 .

↑ Whiteman, Hilary; Gold, Hadas; Saltman, Max (September 23, 2026). " 'Extreme concern' over first known AI hack of a government system" . CNN . Retrieved September 24, 2026 .

↑ Hancock, Sam; Amos, Owen; Watson, Katy (September 24, 2026). "Australia launches urgent review after OpenAI program hacks government health portal" . BBC News . Retrieved September 24, 2026 .

1 2 3 4 Newling, Rob Harris, David Swan, Nick (September 23, 2026). "Three months for OpenAI to alert Australia on Medicare hack, six days to alert ministers" . The Sydney Morning Herald . Retrieved September 24, 2026 .

↑ Elsworthy, Emma; Convery, Stephanie (September 24, 2026). "Albanese says OpenAI hacked Medicare and told Australia months later via email to generic inbox" . The Guardian . ISSN 0261-3077 . Retrieved September 24, 2026 .

↑ Cite error: The named reference armstrong2609 was invoked but never defined (see the help page ).

1 2 Ittimani, Luca (September 26, 2026). "OpenAI says agents leaked 53 images from ChatGPT users in latest example of rogue activity" . The Guardian. Archived from the original on September 26, 2026 . Retrieved September 26, 2026 .

↑ Conger, Kate; Swanson, Ana; Kang, Cecilia (September 25, 2026), "OpenAI's A.I. Went Rogue and Meddled With U.S. Government Websites" , New York Times , ISSN 0362-4331 , retrieved September 26, 2026

↑ Seetharaman, Deepa; Satter, Raphael; Horwitz, Jeff (September 25, 2026). "EXCLUSIVE: OpenAI works to understand full scope of agent activity as user data leak emerges" . Reuters . Retrieved September 25, 2026 .

↑ "The Hugging Face incident and other third-party impact from misaligned models" . OpenAI . September 25, 2026: We identified cases where agents in our research environment transmitted training and evaluation data while using third-party services. Archived from the original on September 26, 2026 . Retrieved September 25, 2026 .

1 2 Franceschi-Bicchierai, Lorenzo (July 22, 2026). "How OpenAI's human mistake led to the AI-powered hack on Hugging Face" . TechCrunch . Retrieved July 25, 2026 .

↑ Woolwine, Wade (July 23, 2026). "What Happened Between OpenAI and Hugging Face?" . Rapid7 . Retrieved July 25, 2026 .

1 2 Koruthu, Bestin; Girard, David (July 23, 2026). "Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It" . Trend Micro . Retrieved August 8, 2026 .

1 2 Newman, Lily Hay (August 5, 2026). "OpenAI Didn't Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree" . Wired . Retrieved August 8, 2026 .

1 2 "OpenAI warns autonomous hacks are 'watershed moment for computer security' " . Cybersecurity Dive . August 6, 2026 . Retrieved August 8, 2026 .

↑ "Did OpenAI's models just breach its own risk 'red line'? Outside safety experts think so" . Fortune . July 25, 2026 . Retrieved July 31, 2026 .

↑ Patel, Dwarkesh (August 30, 2026). "The Rise and Fall of Agent Civilizations" . dwarkesh.com .

1 2 "Its AI agent spent days hacking a company. Sources say OpenAI did not notice for a week" . Reuters . July 24, 2026 . Retrieved July 25, 2026 .

↑ Mowshowitz, Zvi (August 7, 2026). "What Happened: OpenAI and HuggingFace" . Don't Worry the Vase . Retrieved August 9, 2026 .

↑ Mowshowitz, Zvi (August 8, 2026). "OpenAI Trained Its Models For Months While They Coordinated On A Message Board" . Don't Worry the Vase . Retrieved August 9, 2026 .

1 2 3 Sabin, Sam (July 23, 2026). "AI's alarming new skill: Breaking out of the test lab" . Axios . Retrieved July 25, 2026 .

↑ Stokel-Walker, Chris (July 22, 2026). "What OpenAI's rogue agent really did in the Hugging Face hack" . Scientific American . Retrieved July 25, 2026 .

1 2 Abbass, Hussein (July 24, 2026). "OpenAI's models autonomously hacked a tech startup. It signals a seismic shift in cybersecurity" . UNSW Newsroom . Retrieved July 25, 2026 .

↑ McMillan, Robert; Schechner, Sam (July 24, 2026). "How the Futuristic Hack by Rogue OpenAI Models Unfolded" . The Wall Street Journal . Retrieved July 25, 2026 .

↑ Hugging Face Security Team (July 16, 2026). "Security incident disclosure — July 2026" . Hugging Face . Retrieved July 25, 2026 .

↑ Willison, Simon (July 22, 2026). "OpenAI's accidental cyberattack against Hugging Face is science fiction that happened" . Simon Willison's Weblog . Retrieved July 25, 2026 .

↑ "Reps Lieu and Moran introduce bill to require kill switch for AI systems that can cause catastrophic harm" (Press release). Office of Representative Ted Lieu. July 23, 2026 . Retrieved July 25, 2026 .

↑ Kelley, Alexandra (July 23, 2026). "Lawmakers introduce bill mandating kill switches for AI models" . Nextgov/FCW . Retrieved July 25, 2026 .

↑ "Public Citizen Calls for Congressional Investigation Following Reports of Second Company Compromised During OpenAI Rogue AI Incident" (Press release). Public Citizen. July 28, 2026 . Retrieved July 31, 2026 .

↑ "Sam Altman is briefing senators after OpenAI's AI agent escaped and hacked Hugging Face" . Quartz . July 30, 2026 . Retrieved July 31, 2026 .

1 2 "OpenAI's rogue models roamed the internet for 4 days and staged a second attack" . Politico . July 28, 2026 . Retrieved July 31, 2026 .

↑ "1,134 AI staff ask the US for a way to pace AI" . The Web . July 29, 2026 . Retrieved July 31, 2026 .

↑ "Top AI Researchers From Rival Labs Come Together To Ask US Govt To "Pace The Frontier" Of AI" . OfficeChai . July 29, 2026 . Retrieved July 31, 2026 .

↑ "NEWS: Sanders, Casar to Introduce Legislation to Ban Artificial Superintelligence and Temporarily Pause Advanced AI Development » Senator Bernie Sanders" . Senator Bernie Sanders . Retrieved September 4, 2026 .

↑ "Sanders, Casar call for ban on artificial superintelligence" . POLITICO . September 3, 2026 . Retrieved September 4, 2026 .

↑ Duncan, Ian (September 3, 2026). "Sanders proposes ban on 'artificial superintelligence' after rogue AI incidents" . The Washington Post . ISSN 0190-8286 . Retrieved September 4, 2026 .

↑ "California issues investigative subpoena to OpenAI over rogue agents' hacking" . The Guardian . Reuters . October 1, 2026 . Retrieved October 1, 2026 .

↑ "Pacing model development in an era of cyber-critical capabilities" . OpenAI . August 18, 2026 . Retrieved August 18, 2026 .

↑ "Sam Altman (@sama) on X" . X (formerly Twitter) . August 18, 2026 . Retrieved August 18, 2026 .

↑ Bhuiyan, Johana (August 18, 2026). "OpenAI announces slowing pace of development after hack by rogue agent" . The Guardian . ISSN 0261-3077 . Retrieved August 18, 2026 .

↑ Amodei, Dario (September 2026). "We Must Pace the Frontier" . Dario Amodei . Archived from the original on September 20, 2026 . Retrieved September 20, 2026 .

Hugging Face security incident disclosure

OpenAI joint disclosure

Timeline of security hacking incidents

Timeline of computer viruses and worms

Twitter account hijacking

European Medicines Agency data breach

United States federal government data breach

Windows XP Service Pack 1 and Server 2003 RTM source code leaks

Microsoft Exchange Server breach

Ivanti Pulse Connect Secure data breach

Colonial Pipeline ransomware attack

Health Service Executive ransomware attack

Waikato District Health Board ransomware attack

JBS S.A. ransomware attack

Kaseya VSA ransomware attack

Transnet ransomware attack

National Rifle Association ransomware attack

Iranian fuel cyberattack

Red Cross data breach

Anonymous and the Russian invasion of Ukraine

DDoS attacks on Romania

Costa Rican ransomware attack

Shanghai police database leak

Grand Theft Auto VI content leak

Munster Technological University ransomware attack

Insomniac Games data breach

Operation Triangulation cyberattack

British Library cyberattack

Kadokawa and Niconico

Change Healthcare ransomware attack

Ukrainian cyberattacks against Russia

Fur Affinity domain hijacking

IRLeaks attack on Iranian banks

Internet Archive data breach

2024 global telecommunications hack

2024 National Public Data breach

Cyberattacks on Bank Sepah

2025 Paraguay ransomware attack

4chan hacking and data breach

2025 St. Paul cyberattack

Jaguar Land Rover cyberattack

Collins Aerospace cyberattack

2025 cyberattack on Polish power grid

Aura (security) data breach

ManageMyHealth data breach

Neighbourly data breach

Cyberwarfare during the 2026 Iran war

2026 Canvas data breach

2026 OpenAI agent cyberattacks

2026 Minnesota water system cyberattack

Meccha Chameleon malware incident

Grand Theft Auto VI content leak

Anonymous associated events

Google DeepMind Google AI

PrintNightmare (2021)

Account pre-hijacking (2022)

Artificial intelligence controversies

Articles with short description

Short description is different from Wikidata

Use American English from September 2026

All Wikipedia articles written in American English

Use mdy dates from September 2026

Articles lacking reliable references from September 2026

All articles lacking reliable references

Wikipedia articles that are too technical from September 2026

All articles that are too technical

Articles with multiple maintenance issues

Articles containing potentially dated statements from May 2026

All articles containing potentially dated statements

CS1 Spanish-language sources (es)

Articles containing German-language text

Articles with excerpts

CS1 maint: multiple names: authors list

Articles containing potentially dated statements from September 2026

Wikipedia articles in need of updating from October 2026

All Wikipedia articles in need of updating

Pages with reference errors