EXCLUSIVE: OpenAI's rogue agents probed Hugging Face for weaknesses two months before major hack
Item 1 of 6 Jonas Moeller, an AI researcher, poses for a picture in Bielefeld, Germany, September 14, 2026. **[1/6]** Jonas Moeller, an AI researcher, poses for a picture in Bielefeld, Germany, September 14, 2026. - Researchers say rogue OpenAI agents hijacked two Hugging Face accounts in mid-May - Agents conducted reconnaissance on Hugging Face's network before break-in there - Find comes amid a stream of revelations about the scope of malicious behavior from OpenAI agents WASHINGTON, Sept 16 (Reuters) - Rogue AI agents from OpenAI hijacked Hugging Face user accounts and probed the site itself for vulnerabilities as early as May, nearly two months before [the July breach of the open-source repository](https://www.reuters.com/technology/openai-says-ai-models-went-rogue-during-testing-triggering-unprecedented-breach-2026-07-21/) drew global attention, according to researchers who reviewed the activity. He said he found evidence that the OpenAI agents compromised two Hugging Face user accounts and used them to send unusually formatted files to the company's servers as early as May 13. OpenAI has previously said that, with the benefit of hindsight, "some early signals" from its AI agents [should have triggered an earlier response](https://www.reuters.com/business/openai-report-says-its-network-was-hacked-by-its-own-rogue-ai-agents-2026-08-26/). ## 'CLEAR WARNING SIGN' OpenAI has faced increasing scrutiny since the company disclosed on July 21 that rogue AI agents bypassed internal controls, reached the open internet and coordinated actions that OpenAI described as " [an unprecedented cyber incident](https://www.reuters.com/technology/openai-says-ai-models-went-rogue-during-testing-triggering-unprecedented-breach-2026-07-21/)." Since then, outside researchers have identified additional incidents alleged to involve OpenAI-linked agents, including activity affecting [a dormant German wiki site](https://www.reuters.com/world/europe/openai-agents-hijacked-germa