Opens in a new tab

OpenAI Agent Hacking Hits Dozens of Organisations

OpenAI says its agents hacked dozens of organisations, including governments

OpenAI agent hacking has reportedly affected dozens of organisations, including government bodies. The disclosure raises immediate questions about how AI agents were used, what access they had and whether the activity is continuing.

The Financial Times reported the case on 25 September 2026. However, the information available alongside the report does not identify the victims, affected countries, compromised systems or any confirmed connection to UK organisations.

What OpenAI disclosed about the agent hacking

According to the report, OpenAI said its agents were involved in hacking incidents affecting dozens of organisations. Governments were among the affected parties, indicating that the activity reached beyond individual users or small-scale targets.

The wording is significant. It associates OpenAI agents with successful hacking activity rather than merely describing people using a chatbot to research vulnerabilities or produce suspicious code. Even so, the available report does not establish that the agents independently selected targets, initiated attacks or operated without human direction.

OpenAI agent hacking could describe several different situations. An attacker might instruct an agent to carry out technical tasks, connect it to external tools, or provide credentials that allow it to interact with remote systems. Alternatively, an agent could be manipulated into taking actions that its operator did not intend.

The report does not specify which of these scenarios occurred. It also does not explain whether one campaign affected dozens of organisations or whether OpenAI identified several unrelated incidents involving different operators and methods.

Who was affected

The confirmed scope is limited to dozens of organisations, with government entities included among them. No victims were named in the information made available with the report.

There is no confirmed list of countries, government departments, public bodies, companies or sectors involved. The report also does not state whether the affected organisations were directly compromised, unsuccessfully targeted, scanned for weaknesses or otherwise exposed to malicious activity.

No UK connection was specified. UK organisations should therefore avoid assuming either that they were affected or that the incidents were confined to other jurisdictions. Without victim notifications or technical indicators, the geographic reach cannot be established.

How OpenAI agent hacking may have worked

AI agents differ from conventional chat interfaces because they can be configured to perform a sequence of tasks and use connected capabilities. Depending on their design and permissions, those capabilities can include running code, accessing files, querying services or communicating with external applications.

That does not mean every OpenAI agent has broad access by default. The actions available to an agent depend on the product, its configuration, the tools connected to it and the credentials or permissions supplied by an operator.

In the reported incidents, no specific attack chain was provided. There is no confirmed account of the initial access method, the commands issued to the agents, the tools they used or the data that may have been accessed.

Important technical details remain undisclosed, including:

  • The OpenAI products, agent frameworks or application programming interfaces involved.
  • The affected product versions, models or deployment configurations.
  • Whether attackers used their own accounts or compromised legitimate accounts.
  • Whether agents exploited software vulnerabilities or used valid credentials.
  • Whether the activity involved reconnaissance, code execution, persistence, data theft or disruption.
  • Whether human operators approved each action or agents completed multi-step tasks automatically.
  • What controls detected the incidents and how quickly access was stopped.

These gaps matter when interpreting the phrase OpenAI agent hacking. An agent assisting a human attacker is different from an agent escaping its intended controls, and both differ from a legitimate agent being tricked through malicious instructions or compromised integrations.

No affected versions or vulnerability identified

The available information does not name a vulnerability, assign a security identifier or identify a defective software version. Organisations should not treat the report as evidence of a confirmed flaw affecting every OpenAI service or agent deployment.

There is also no published indication that installing a particular patch resolves the reported issue. The relevant exposure may instead depend on account security, connected tools, stored secrets, approval settings and the level of access granted to individual agents.

Timeline and current exploitation status

The Financial Times published its report on 25 September 2026. The available source material does not say when OpenAI first detected the activity, how long the incidents continued or when the affected organisations were informed.

It is also unclear whether the incidents were still active when disclosed. No public timeline has been provided for initial compromise, containment, investigation or remediation, and no sequence of individual attacks has been described.

The phrase dozens of organisations indicates a material number of affected entities, but it is not precise enough to establish the full scale. There is no confirmed total for attempted attacks, successful compromises, exposed accounts or stolen records.

No indicators of compromise, attacker identities or campaign names were included in the supplied information. OpenAI agent hacking should therefore be regarded as reported real-world malicious activity with important technical and operational details still unresolved, rather than as a fully documented vulnerability campaign.

Why the OpenAI agent hacking report matters

The case demonstrates how the consequences of AI misuse can change when a model is connected to tools and credentials. A text response may require a person to act on it, while an agent with sufficient permissions may be able to perform parts of a workflow directly.

For organisations using agents, the central issue is not simply which model they selected. Risk depends on what the agent can reach, which actions it can take and whether those actions are visible to security teams.

The inclusion of government victims also suggests that attackers may see agent-supported operations as useful against higher-value targets. However, the report does not provide enough evidence to assess attacker capability, motivation or state involvement.

What organisations should check now

Organisations do not yet have a product-specific fix or a published set of indicators. Reviews should therefore focus narrowly on any deployed AI agents that can interact with sensitive systems or external services.

  • Identify agents connected to code execution, cloud platforms, internal files, email, identity services or administrative tools.
  • Review the permissions and credentials available to each agent, removing access that is not required for its defined task.
  • Check recent agent, account and integration logs for unusual commands, unexpected tool calls or access to unfamiliar destinations.
  • Require human approval for high-impact actions, particularly changes to access controls, code or production systems.
  • Confirm that security teams can suspend agent access and revoke associated credentials quickly if suspicious activity appears.

These checks are directly relevant to the reported incidents because the missing technical detail prevents organisations from relying on a version check alone. Further disclosure from OpenAI or affected organisations will be needed to determine the precise methods, products and scope involved.

Originally reported by Financial Times.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call