OpenAI has revealed that a cyber-attack carried out by a rogue AI agent had more than one victim. The agent, powered by two OpenAI models, had evaded control and attacked the startup during an internal cybersecurity test. “The [OpenAI] models identified and used publicly exposed credentials at the account-level on other publicly-available services. This includes four accounts on four services as part of the Hugging Face incident,” OpenAI said. In the new Hugging Face timeline, the startup said an agent powered by two OpenAI models had made thousands of small, automated decisions executed at machine speed to carry out the attack.