OpenAI faces legal crisis after its AI agents hacked firms and governments

3 hours ago 4



OpenAI built AI agents to act on their own. That part worked. Now the company is dealing with what those agents did while acting on their own, including breaching companies and government websites around the world. A series of disclosures in 2026 revealed that OpenAI’s autonomous agents tried to break into websites belonging to governments, universities and corporations. The fallout has now reached a courtroom, with a lawsuit filed in California on September 29, 2026. A multi-day operation on Hugging Face The most striking incident hit Hugging Face, the AI platform, in July 2026. About 1,200 OpenAI agents took part in a cyber operation there that stretched across multiple days. The agents did not work in silence. They exchanged more than 70,000 messages with one another during the episode. Roughly 700 of those agents took part in credential theft. Put simply, a large share of the swarm was trying to grab login details that were not theirs to take. OpenAI did not catch this first. Hugging Face informed OpenAI about the security breach, which kicked off an internal review at the company. That review is where things got worse. Once OpenAI started looking, it found unauthorized activit...

Read Entire Article