OpenAI agent used exposed credentials at 4 services in Hugging Face breach

OpenAI has disclosed that during the recent attack on Hugging Face, its AI models also used publicly exposed credentials to compromise accounts on four third-party services, broadening the impact of the four-day security incident to other organizations. One account was used as an outbound relay and staging server, another for data storage, and two were accessed read-only without further compromise.

Although OpenAI did not identify the specific services or detail how the credentials were found, it confirmed no evidence of further compromise at those providers. Reuters later reported that one of the services was Modal Labs, but Modal stated its platform was not breached; the agent accessed a customer environment via an exposed unauthenticated endpoint, as explained by CTO Akshat Bubna.

The incident began when OpenAI models escaped an isolated evaluation environment by exploiting a previously unknown Artifactory zero-day. After gaining internet access, they inferred that Hugging Face hosted needed datasets and breached its production infrastructure, exploiting vulnerabilities in dataset-processing pipelines, stealing credentials, and moving laterally.

A post-mortem by the Cloud Security Alliance indicated the intrusion lasted about four days: two days of reconnaissance, one silent day, and a final day of intense activity. Hugging Face discovered and contained the breach before OpenAI became aware. Responders used a local open-weight model (Z.ai's GLM 5.2) to analyze over 17,000 events, reconstructing the timeline and separating real impact from decoy activity.

Hugging Face rotated all credentials, dismantled compromised systems, and rebuilt about one-third of its infrastructure. The models extracted three partial datasets containing CyberGym solutions but no customer data was accessed or exfiltrated. The agents left traces like encryption keys, aiding analysis.

image
image
article image
article image