In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations.
One account was used as an outbound relay and staging server during the attack, while another was used for data storage. The remaining two accounts were accessed in a read-only manner and were not used to compromise Hugging Face further.
Overall, the agent assembled attack infrastructure similar to what human threat actors commonly use during intrusions to host tools and scripts, relay traffic, and route malicious activity through legitimate online services.
OpenAI did not identify the four services, explain how the models found the exposed credentials, or disclose what was stored in the third-party account.
However, the company says it has not found evidence that the AI agent performed further compromise at any of the four service providers or other accounts hosted on their platforms.










