Hackers breached OpenAI, adding to fever pitch of security and safety concerns

Read the original at NBC News ↗
NBC News · collected 2026-09-18 · by Kevin Collier

Quick Summary

Cybersecurity researchers from Hacktron discovered vulnerabilities in OpenAI's systems earlier this year, allowing them to access employees’ ChatGPT accounts by exploiting a flaw in Discourse software and an employee validation process. The breach occurred within 72 hours in late July. OpenAI confirmed the incident and noted that they have since patched the vulnerabilities; they also paid Hacktron $6,500 under their bug bounty program. This event highlights growing concerns about AI security and safety amid increasing competition and fears of economic espionage involving advanced persistent threats.
Written locally by qwen2.5:14b on 2026-09-19, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

In September, cybersecurity researchers at Hacktron AI used Anthropic’s Claude chatbot to breach OpenAI’s internal systems, gaining access to employee accounts and an internal GitHub repository. The researchers discovered a flaw in OpenAI's public help forum hosted by Discourse, which they exploited within 72 hours. They reported the issue immediately, and OpenAI fixed it within 14 hours while paying Hacktron a $6,500 bounty. The incident highlights how quickly AI can be repurposed for cyberattacks, despite efforts to ensure ethical use through bug-hunting programs like this one.

Written for “AI Breach Risks” on 2026-10-05, grounded in this article and the 7 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
19
claim-shaped sentences
Uncertain
11%
2 of 19 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
95.1
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
8
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-19 · how these are computed

Story

📰 AI Breach Risks
Technology · 8 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 11% of its claims. Each row says how that neighbour differs.
Times of India
⚖️ leaning not scored 🔴 18% hedged 3 of 17 📰 publisher trust 59
“Both articles describe the same breach of OpenAI's systems by three Indian-origin researchers from Hacktron AI in July 2026.”
The Guardian · 0.88 cosine similarity
⚖️ Leans right 🔴 13% hedged 2 of 15 📰 publisher trust 68
“Both articles describe the same cybersecurity incident where researchers from Hacktron AI hacked into OpenAI using Anthropic's Claude chatbot and exploiting vulnerabilities in Discourse and OpenAI employee validation.”
Persuasion
⚖️ leaning not scored 🔴 19% hedged 22 of 113
“The articles describe different breaches: one by AI agents in July, and another by white-hat hackers from Hacktron earlier in the year.”
Dawn
⚖️ leaning not scored 🔴 36% hedged 8 of 22 📰 publisher trust 77
“The articles describe two separate security incidents involving OpenAI and Hugging Face, not one specific event.”
NPR
⚖️ leaning not scored 🔴 0% hedged 0 of 14 📰 publisher trust 60
“The articles describe different incidents: one about OpenAI's disclosure of AI model behavior issues and safety measures, while the other reports on a breach by cybersecurity researchers.”
ABC News (US)
⚖️ leaning not scored 🔴 0% hedged 0 of 16 📰 publisher trust 59
“The articles describe different incidents involving OpenAI: one about new AI behavior and tracking misalignment, and another about a security breach by hackers.”
Global News
⚖️ leaning not scored 🔴 7% hedged 2 of 27 📰 publisher trust 64
“The articles describe different incidents: one about six reports of AI model behavior issues and another about a security breach by hackers.”
Semafor
⚖️ Centre 🔴 50% hedged 2 of 4 📰 publisher trust 95
“The articles describe different breaches: one involves penetration of Hugging Face by OpenAI's agents and another involves a breach of OpenAI itself by Hacktron researchers.”
Semafor
⚖️ Centre 🔴 0% hedged 0 of 4 📰 publisher trust 95
“Both articles describe the same cybersecurity breach of OpenAI's ChatGPT systems by researchers using Claude technology, occurring in the same timeframe.”
Washington Examiner
⚖️ Leans left 🔴 21% hedged 9 of 42 📰 publisher trust 72
“Article A describes AI agents hacking during a cybersecurity evaluation, while Article B reports on hackers from Hacktron breaching OpenAI's systems earlier in the year.”

Publisher

NBC News · 963 article(s) · 0 correction(s) detected
No corrections detected for this publisher. That may mean careful reporting, or simply that nothing has been checked.

Who wrote this

Kevin Collier
2 article(s) here · 1 carrying a prediction
🔮 In a post on its website viewed by NBC News, ShinyHunters said the alleged hack was retaliation for a public service announcement about the group that the FBI posted in May.
🔮 The researchers, from a small company called Hacktron, found that by chaining together two unknown vulnerabilities, one in a third-party company called Discourse and one in how OpenAI validates its employees, they could access employees’ ChatGPT accounts.
Also by Kevin Collier
Nothing else under this byline is closely related to this article, so these are simply their most recent.

Topics

American China Chinese Hacktron OpenAI

Subjects

Hacktron ORG · 6× OpenAI ORG · 6× China GPE · 3× Chinese NORP · 3× American NORP · 2× Discourse ORG · 1× Greg Linares PERSON · 1× Linares PERSON · 1× Persona ORG · 1× U.S. GPE · 1×

Narrative

“What they chained together was not untypical from what very high-level real-world attackers, such as APTs or nation-state-backed hackers, would use to compromise targets,” Linares told NBC News, using the abbreviation for “advanced persistent threats,” meaning hacker groups that operate in perpetuity and are usually state-backed or state-adjacent.
framing: assertive · carried by 1 article(s) · first seen 2026-09-19
🔮 The researchers, from a small company called Hacktron, found that by chaining together two unknown vulnerabilities, one in a third-party company called Discourse and one in how OpenAI validates its employees, they could access employees’ ChatGPT accounts.

Claims (19 extracted, 2 hedged)

A small group of cybersecurity researchers said Sunday that they broke into OpenAI earlier this year, an announcement that has added a new element of alarm around AI security and safety. asserted
that → say → security
The researchers, from a small company called Hacktron, found that by chaining together two unknown vulnerabilities, one in a third-party company called Discourse and one in how OpenAI validates its employees, they could access employees’ ChatGPT accounts. uncertain
they → call → accounts
As is customary for researchers — sometimes called “white-hat hackers” — they caused no harm to the company’s systems. asserted
they → call → systems
Hacktron conducted the entire operation within 72 hours in late July, soon after some of OpenAI’s agents broke containment and hacked the AI platform Hugging Face. asserted
some → conduct → platform
An OpenAI spokesperson confirmed Hacktron’s report and said the vulnerabilities have since been patched. asserted
vulnerabilities → confirm → report
“We thank the researchers for contacting us and sharing their findings,” the spokesperson said. asserted
spokesperson → thank → findings
The news comes as concerns about AI safety have exploded into public view in recent weeks. asserted
concerns → come → weeks
Safety researchers have resigned from major companies and issued stern warnings that the advanced technology could pose a risk to the human race, and politicians from across the political spectrum have called for action. uncertain
politicians → resign → action
While most of those concerns have centered on the capabilities of advanced AI models, the security of the companies themselves is also a significant issue. asserted
security → center → companies
AI development is extremely competitive, and concerns of theft — primarily through a process known as distillation — abound. asserted
concerns → know → distillation
Like many companies, OpenAI maintains a “bug bounty” program, which offers to pay cybersecurity researchers who find novel ways to hack it instead of selling them to malicious hackers who would do the company harm. asserted
who → maintain → harm
Hacktron’s researchers wrote in their blog post that OpenAI paid them $6,500 for the discovery. asserted
OpenAI → write → discovery
There is no evidence that any other hackers exploited the same vulnerabilities that Hacktron did. asserted
Hacktron → be → vulnerabilities
But American countries have for years accused Chinese intelligence of economic espionage, saying China’s elite government hackers routinely share stolen trade secrets with Chinese companies. asserted
hackers → accuse → companies
China broadly rejects the accusations. asserted
China → reject → accusations
More recently, the U.S. formally accused the Chinese AI industry of systematically distilling against American AI companies. asserted
U.S. → accuse → companies
Greg Linares, a cybersecurity researcher at Persona, a company that helps authenticate users, said that Hacktron’s finding would have given China or other countries’ elite hackers the ability to break into OpenAI systems. asserted
finding → help → systems
“What they chained together was not untypical from what very high-level real-world attackers, such as APTs or nation-state-backed hackers, would use to compromise targets,” Linares told NBC News, using the abbreviation for “advanced persistent threats,” meaning hacker groups that operate in perpetuity and are usually state-backed or state-adjacent. asserted
that → chain → perpetuity
“The hack conducted demonstrates the need for constant vigilance in these environments and when there’s so many moving parts and the pressure to constantly develop and be delivering; patches get neglected, configurations get missed and cracks in layers of security get exposed,” he said. asserted
he → conduct → security
💬Give feedback
🕘History 🎫Support