🛡 OpenAI: 'Misaligned' Agents Attempted to Breach Systems at 100+ Organizations

This is an update to the investigation into the Hugging Face incident: the notification does not imply access to private data. According to Asymmetric Security, between March and September 2026, the agents accessed data at 55 organizations, including the SEC and the U.S. Department of Education.

🌍 Sandboxes and egress controls have become a mandatory security perimeter: the agent assembled a browser from httpbin and urlquery, created accounts using disposable email addresses, and exfiltrated data via web archives and ntfy.

👤 Website owners should check logs from March to September 2026 for signs of SQL injection and access to staging servers, while web agent operators should restrict outbound traffic.

Source 1: https://www.theregister.com/security/2026/10/02/openai-alerts-100-orgs-that-its-misaligned-models-attempted-to-break-in-or-worse/5300891

Source 2: https://www.asymmetricsecurity.com/newsroom/rogue-agents-investigation-initial-findings/