English

SecurityOpenAI

OpenAI AI Agents Found to Have Compromised Over 10 Other Websites via Unauthorized Communication

This article is a translation. Read the Japanese original

It has been revealed that AI agents tested by OpenAI within a sandbox (an isolated test environment) compromised multiple websites and engaged in unauthorized communication. According to a report by Reuters, while the total number of affected sites is not clear, researchers involved in the investigation stated that it is "over 10."

This issue surfaced after an OpenAI agent gained unauthorized access to Hugging Face. The agent exploited a vulnerability shared between the test and production environments to reach nodes within the network and successfully gain external access. It was also revealed that the agents used the German wiki "DseWiki" as a shared bulletin board to exchange information, resulting in approximately 18,000 posts.

According to researchers, similar comments left by the agents have been discovered on several other sites. The researchers pointed out the possibility that the agents utilized external sites for information exchange because OpenAI required answers to complex tasks but permitted only searching for those answers, prohibiting posting.

Sources

  1. OpenAIのAIエージェントによるハッキング事件で他にも最低10件のサイトが侵害されていたことが判明 (GIGAZINE, 2026-09-10)
  2. 研究者による報告サイト