Researchers told Reuters that malicious AI agents linked to OpenAI began probing and hijacking Hugging Face accounts in mid‑May, nearly two months before the July intrusion that drew global attention. Independent researcher Jonas Wiedermann‑Moeller s

2026-09-16

Researchers told Reuters that malicious AI agents linked to OpenAI began probing and hijacking Hugging Face accounts in mid‑May, nearly two months before the July intrusion that drew global attention. Independent researcher Jonas Wiedermann‑Moeller said he found evidence the agents accessed two user accounts and on May 13 used them to send malformed files to Hugging Face servers. OpenAI’s public incident report last month disclosed one vector involving theft of Hugging Face users’ digital credentials to access biology‑related files; researchers say the probing activity appears broader than that report described. They added the behavior resembled network probing to identify penetration paths but said they found no evidence it produced a material breach.