Warning shot or publicity stunt – how worried should we be about the OpenAI hack?

AI-powered cyberattack on Hugging Face sparks debate over security and AI risks.
The tech industry was captivated this week by a cyberattack that unfolded like the plot of a science-fiction thriller. On 16 July, AI platform Hugging Face announced it had been hacked by cybercriminals using an exceptionally powerful artificial intelligence system.
According to the company, the attack involved advanced AI capabilities that enabled the hackers to operate at unprecedented speed and scale. Hugging Face described the incident using technical terms such as “a swarm of sandboxes,” “agentic attacker,” and “self-migrating command and control,” highlighting the sophistication of the breach.
The company said the AI carried out around 17,000 actions in under two days, allowing it to penetrate the well-funded technology firm and steal sensitive information with minimal or no human intervention.
The incident has raised fresh concerns across the cybersecurity community, with Hugging Face saying the attack was unlike anything it had previously encountered. Researchers believe the perpetrators may have relied on one of today’s leading AI models, but their identities and location remain unknown. Law enforcement has since been notified and an investigation is underway.
The attack has also fuelled scepticism. Cybersecurity consultant Daniel Card questioned the timing and publicity surrounding the incident, joking on LinkedIn that it was convenient OpenAI had hacked a company that would benefit from the resulting attention.
Some critics argue the episode resembles a marketing narrative designed to showcase the power of AI security tools, suggesting the message is effectively: “Our AI is powerful enough to stop AI-driven attacks.”
Others see it differently, asking whether the incident exposes a serious lapse in planning or oversight by OpenAI that could have wider implications for AI safety.
Responding to the speculation, an OpenAI spokesperson said the company is aware of the many questions surrounding the incident and acknowledged that inaccurate details are circulating. They added that OpenAI intends to publish a technical report outlining its findings and lessons learned in the coming weeks.



