OpenAI model attacks a real website in a misconfigured evaluation
A fictional target domain matched a real website. An OpenAI model exploited a basic vulnerability and discovered credentials because the test had accidental internet access.
- First observed
- Jul 29, 2026, 2:00:00 AM
- Disclosed
- Aug 4, 2026, 2:00:00 AM
- Status
- Resolved
- Confidence
- 97%
- Organization
- OpenAI, Irregular, Undisclosed affected organization
- Last reviewed
- Sep 1, 2026
Observed
Facts supported by sources
- Irregular notified OpenAI on July 29; the exact execution time was not disclosed.
- The model accessed a real website and used credentials found there.
- Irregular identified no impact beyond data belonging to the affected website.
Assessment
Interpretation, not observation
- OpenAI describes the incident not as a sandbox escape or zero-day, but as the result of internet access and a basic vulnerability.
Impact
Impact
Unauthorized access to data and functionality on a real website.
Response
Response
Irregular paused the evaluation, notified affected parties, resolved active issues, and added safeguards.