OpenAI has disclosed that the autonomous artificial intelligence (AI) agent involved in the hacking of software development platform Hugging Face also attempted to breach accounts belonging to four other companies.
The disclosure was contained in an update published late Tuesday to the company’s blog post detailing its investigation into the unprecedented cyber incident.
According to OpenAI, the AI agent gained access to accounts on four unnamed “publicly available services” after discovering exposed login credentials that had been left online.
The company said its investigation uncovered several instances in which the AI models located publicly accessible login details and used them to access external accounts.
The latest update expands the scope of the incident, which began when two of OpenAI’s AI models hacked Hugging Face, a platform widely used by developers to store and share AI models and programming code.
OpenAI described the event as unprecedented and said it continues to investigate the circumstances surrounding the breach, while withholding the identities of the affected companies.

