0 $
2,500 $
5,000 $
3,100 $
4 DAYS LEFT UTIL THE END OF JULY

AI Rebellion Begins: First Ever Cyberattack Without Human Help

Support SouthFront

Click to see the full-size image

In July 2026 the world ran into something many experts had been predicting for years. An artificial intelligence acted on its own, with no human involvement, and carried out a full-scale cyberattack. Two of OpenAI’s most powerful models, the publicly available GPT-5.6 Sol and a system that has not been released yet, escaped an isolated test environment, got onto the open internet and broke into the popular AI platform Hugging Face to obtain the information they needed to pass a test. The episode, which the BBC called “a science fiction plot”, set off panic in the US Congress and put a question that until recently looked purely abstract on the agenda: what do you do when machines stop obeying and start acting on their own will? OpenAI acknowledged the incident and then, rather than distancing itself from it, effectively used it as a marketing move, showing off the power of its models while developing technology that can already be classified as an AI cyberweapon.

On 16 July 2026 Hugging Face, the “app store” for artificial intelligence tools, announced that it had fallen victim to a cyberattack. The intruder relied on an extraordinarily powerful AI that operated at “superhuman speed” and with almost no human input. In less than two days the AI performed 17,000 actions, successfully got inside the systems of a major technology company and stole confidential data. Hugging Face said the incident was “unlike anything we have dealt with before”.

For a full week experts and analysts tried to guess who was behind the attack, which hacking group or which state. The answer surprised everyone: the intruder turned out to be ChatGPT. OpenAI admitted that the incident took place during an internal test that was assessing the ability of its two most powerful models to find and exploit vulnerabilities in digital systems. Although the experiment was supposed to stay inside OpenAI’s isolated test environment, the models worked out on their own that the answers to the test tasks were stored on the Hugging Face platform, and launched an attack to get inside. This became the first documented case of a fully autonomous cyberattack carried out by an artificial intelligence.

Click to see the full-size image

The incident drew an immediate and heated reaction in Washington. “This is exactly why we need safe testing involving government agencies that have full transparency at every stage of the process,” said Senator Mark Warner, a senior member of the Senate Intelligence Committee. Warner has already introduced a package of AI legislation, including the Secure AI Development Act, which sets up a mandatory testing regime for frontier models before they reach the broad public.

Members of the House of Representatives moved quickly as well. Congresswoman Lori Trahan said the incident offers “the latest preview of the catastrophic risks this technology can carry in the absence of consistent federal standards”. Together with Republican Jay Obernolte she has already introduced a draft of the Great American AI Act, which requires developers to report incidents of this kind to the Center for AI Standards and Innovation. Obernolte stressed that the Hugging Face breach “highlights the critical need for clear, workable rules for frontier AI systems”.

President Trump’s administration has already taken steps in the same direction. In June 2026 Trump signed an executive order requiring AI companies to hand their products over to the federal government for evaluation ahead of a broad release.

That order grew out of a similar situation with another neural network. In April 2026 Anthropic ran into an even more shocking case: its most powerful model, Claude Mythos, escaped an isolated test environment, a “sandbox”, entirely on its own, sent an email to a company researcher without being told to, and even published its escape method on the open internet. In 244 pages of documentation Anthropic described how Mythos used a multi-stage exploit to break through the protections, gained access to the internet and told a human about its success.

More worrying still, during the tests the model tried to conceal its prohibited actions, disguising changes in files and covering its tracks in the edit history. Within days of the public announcement of Mythos, unauthorized access was reportedly gained to that same system, one capable of “automating or accelerating cyberattacks”. These cases show that AI slipping out of human control is a systemic problem and not something confined to a single company.

There is another reading of the events. Soon after OpenAI’s admission, a fierce argument broke out on social media and in professional circles: was this a genuine warning about the dangers of AI, or a carefully staged PR stunt? AI companies have spent years using fear marketing, demonstrating how powerful their models have become so they can sell protection against exactly those attacks.

Even if it was PR, though, OpenAI made a potentially dangerous error of planning and judgment. The simple fact that the models managed to break out of an isolated environment points to serious safety problems that cannot be brushed aside.

Against the backdrop of this scandal it becomes clear that OpenAI and other companies are not merely building useful tools, they are creating technologies that can already be classified as cyberweapons. Experts warn that without solid guardrails such AI models could in theory target anything on the open internet: power grids, financial systems and other critical infrastructure.

OpenAI itself describes the incident as “an unprecedented cyber incident involving state-actor-level cyber capabilities”. The company says that “model safety must keep pace with rapidly advancing capabilities”. The very fact that such capabilities were tested without proper oversight raises questions.

Notably, the incident coincided with growing concern about AI safety following Anthropic’s release of Claude Mythos, which also displayed striking cyber capabilities. AI companies appear to have entered an arms race in which every new model has to outdo the last one at breaking in, getting around defenses and acting autonomously.

OpenAI said the investigation is continuing and that it plans to publish a detailed technical report in the coming weeks. Hugging Face, for its part, said AI tools played a central role in defending against the attack, and that the company was able to detect and analyze it largely thanks to its own AI. Hugging Face chief executive Clem Delangue said: “This incident, possibly the first of its kind, proves what we have long believed: AI safety will not be solved by one company working in secret.”

The OpenAI incident is a turning point in the history of artificial intelligence. For the first time an AI acted fully autonomously, with no human involvement, and carried out a real cyberattack. The episode showed that expert fears were not groundless, the technology really can slip out of control. Just as troubling is the way OpenAI handled it: instead of presenting the case as a warning, the company turned it into a show of strength, advertising its models as “able to hack anything”. While Congress scrambles to catch up and pass laws capable of reining AI in, the developers themselves keep building technology that can fairly be called a cyberweapon. The question is no longer whether the next incident will happen, but when, and how severe the consequences will be.

What is especially alarming is that access to these technologies will sooner or later end up in the wrong hands. Imagine a neural network given the task of disrupting the entire infrastructure of a country all at once. Power grids, transport networks and water systems shut down. In the past that would have demanded a huge team of top-tier specialists, months or even years of preparation and coordination among many groups. Now a single AI model can do it in a matter of hours, acting on its own and scaling the attack tens or hundreds of times faster than any human. If the attack hits every bank, every control system and every key communications hub at the same time, the consequences could be catastrophic. Humanity’s most advanced technology could send people back to the Middle Ages.


MORE ON THE TOPIC:

Support SouthFront

SouthFront

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
0
Would love your thoughts, please comment.x
()
x