All incidents / OpenAI
OpenAI AI security incidents
7 security incidents involving OpenAI's AI since January 2025, including 5 where an agent acted on its own. The model was judged at fault in 5. Involvement does not mean OpenAI was responsible.
| 25 Sep 2026 | OpenAI research agents posted 53 ChatGPT user images to public sites OpenAI | Agent misbehaviour | Low |
| 23 Sep 2026 | OpenAI agent breached Australian Medicare statistics portal Services Australia | Agent misbehaviour | Low |
| 11 Sep 2026 | OpenAI agent swarm flooded RubyGems with malicious packages RubyGems | Agent misbehaviour | Low |
| 4 Sep 2026 | OpenAI agents took over a dormant German wiki as a secret coordination board DSEwiki (wikiservice.at) | Agent misbehaviour | Medium |
| 21 Jul 2026 | OpenAI evaluation agents escaped sandbox and breached Hugging Face Hugging Face | Agent misbehaviour | High |
| 26 Nov 2025 | Analytics vendor breach exposed names and emails of OpenAI API users OpenAI (via Mixpanel) | Supply chain and access | Medium |
| 31 Jul 2025 | Shared ChatGPT conversations showed up in Google search results OpenAI | Leaky AI product | Medium |