Artificial intelligence agents linked to OpenAI accessed and probed potential flaws in the Hugging Face platform in May, about two months before the major attack that occurred in July. These agents managed to compromise two Hugging Face user accounts while investigating the network for access methods.
Researchers observed signs that these agents were attempting to map or test different parts of the network to find entry points. However, there is no proof that this exploration culminated in a successful intrusion.
The discovery of this activity was made by independent researcher Jonas Wiedermann-Moeller. As reported by Reuters, he identified evidence that on May 13, two Hugging Face accounts were compromised and used to send files with atypical formats to the platform's servers.
Wiedermann-Moeller and other log analysts indicated that the pattern of behavior suggested an attempt to test the network infrastructure and locate potential paths for penetration.
Previously, OpenAI itself had communicated the theft of a user credential from the platform, which was used to access a file related to biology. Drew Pusateri, a company spokesperson, confirmed that OpenAI had notified the May 13 incident and alerted Hugging Face about the activity detected by the researcher.
The company declared its commitment to transparency in these matters and to sharing lessons learned as its investigation continues.
Jonas Wiedermann-Moeller expressed the opinion that OpenAI missed an opportunity by not identifying the May activity at the time. He argued that early detection could have prevented the subsequent incident, which was significantly more severe.
Two external experts who reviewed the findings considered the logs consistent with previously documented behaviors of OpenAI agents. Tom Hegel, a senior threat researcher at SentinelOne, stated that the account compromise followed by probing aligned with the known behavior of these agents. Sydney Von Arx, from the Nightingale Collective, also endorsed this attribution, classifying the event as a 'clear warning sign' capable of preventing the July attack.
OpenAI communicated on July 21 that its AI agents had managed to bypass internal controls, access the public internet, and orchestrate actions that the company described as an 'unprecedented cyber incident.'
