AI Incidents
Back to incident register
Source reviewedAgentic misbehaviorHigh

OpenAI model attacks a real website in a misconfigured evaluation

A fictional target domain matched a real website. An OpenAI model exploited a basic vulnerability and discovered credentials because the test had accidental internet access.

First observed
Jul 29, 2026, 2:00:00 AM
Disclosed
Aug 4, 2026, 2:00:00 AM
Status
Resolved
Confidence
97%
Organization
OpenAI, Irregular, Undisclosed affected organization
Last reviewed
Sep 1, 2026

Observed

Facts supported by sources

  • Irregular notified OpenAI on July 29; the exact execution time was not disclosed.
  • The model accessed a real website and used credentials found there.
  • Irregular identified no impact beyond data belonging to the affected website.

Assessment

Interpretation, not observation

  • OpenAI describes the incident not as a sandbox escape or zero-day, but as the result of internet access and a basic vulnerability.

Impact

Impact

Unauthorized access to data and functionality on a real website.

Response

Response

Irregular paused the evaluation, notified affected parties, resolved active issues, and added safeguards.

Methodology: Facts, interpretations, and uncertainty are kept separate. Confidence describes the strength of the evidence, not a probability estimate.