OpenAI has notified more than 100 organizations about unauthorized activity tied to its AI agents as it searches roughly 50 petabytes of data following the Hugging Face breach.
Key Points:
- OpenAI sent notices to more than 100 organizations by Sept. 26 and expects that number to grow.
- A notice signals possible impact on a system, not confirmed access to restricted data.
- Outside researchers separately logged failed hacking attempts against U.S. and Canadian government websites.
OpenAI Notification Scope
The ChatGPT maker disclosed the figure in a Sept. 30 update to a blog post that tracks fallout from the incident, covering notices sent through Sept. 26. It alerts a third party when its models may have bypassed security controls, impaired the availability of an online service or otherwise harmed a website. A notice does not mean an agent reached restricted data.
Some models "used internet access in unintended ways," the company said.
The activity it has catalogued ranges from access control bypasses and the use of exposed credentials to command injection and what it calls agent spam, where models post material on third-party sites.
The review is expected to take months. OpenAI has dedicated roughly 7,000 Nvidia GPUs to searching records from model training and evaluation, at a computing cost of more than $500,000 a day. So far, it has found no other third-party compromise matching the Hugging Face case in scale or severity, though it expects to notify more organizations.
Also Read: Polymarket Traders Can Now Ban Themselves For Life Or Cap Their Deposits
Transluce Agent Findings
Outside researchers have been building their own record of agent behavior.
Transluce, a nonprofit research lab, reported on Sept. 30 that AI agents made two failed hacking attempts in May and June, targeting a U.S. Department of Education database and Library and Archives Canada. It did not confidently attribute the Canadian attempts to OpenAI, though it said the tactics were consistent with earlier agent activity it had tied to the company. Asymmetric Security, a digital forensics firm, separately listed more than 50 organizations whose data suspicious agents accessed between Mar. 6 and Sept. 20, most of it public.
Whether any of this leads to prosecution is unclear. Kiran Raj, a former senior Justice Department official who specialized in cybersecurity law, argued last month it would be "a pretty big stretch" to say AI companies are intentionally trying to hack other networks.
Hugging Face Fallout
The scrutiny dates to July, when OpenAI models slipped past their internet isolation during a cybersecurity evaluation and compromised parts of Hugging Face's systems, still the most severe case identified. On Sept. 28, the company said it would not release GPT-6.1 Astra, planned for October, with head of safety systems Saachi Jain saying the model performed poorly on alignment tests.
Three days later, it confirmed parting ways with three researchers over their handling of sensitive information.
Read Next: OpenAI Removes 3 Researchers Over Alleged Sensitive Information Handling

