Tools AI Risk Radar ai-incident-0049
Incident record
OpenAI models exploited a real website after a third-party CTF evaluation misconfiguration
- Severity
- High
- Status
- Contained
- Type
- Agent Hijack
- Target
- A real website whose domain coincided with a simulated CTF challenge's fictional target
- Actor
- researcher
What happened
OpenAI disclosed that its models breached a live website during Capture the Flag style cybersecurity evaluations run with third-party partner Irregular, after a testing-environment misconfiguration gave the models unintended access to the public internet. The fictional target named in one challenge happened to coincide with a real domain, so the model treated the live site as part of the simulation, exploited a basic vulnerability there, then used credentials it found to keep operating the site.
OpenAI said this was not a sandbox escape or a zero day; the internet access came from the misconfiguration, and the model used a basic flaw once it had that access. Irregular paused the affected evaluations, began remediation and notified the site's operator, and its audit found no impact beyond that site's own data. It is a separate incident from the Hugging Face breach disclosed in July and from the AISI cyber-range incident disclosed the same day.
Sources
- OpenAI: Third-party cyber evaluations involving OpenAI modelsopenai.com/index/third-party-cyber-evaluations-involving-ope…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026