Researchers claim OpenAI employee account takeover via two bugs
Is this a scandal?
Not yet — an early signal. Noise 43/100, holding steady, across 1 source.
OpenAI will likely issue a security advisory or silent patch confirmation because silence invites regulatory scrutiny and erodes enterprise trust after such specific public claims.
Noise 43/100 — louder than 99% of tracked AI controversies.
Why it matters
Alleged access to internal codebases and connected services highlights critical supply chain risks in AI infrastructure security.
Key points
- Researchers S1r1u5_ claim they exploited two bugs to hijack OpenAI employee accounts on July 25.
- The alleged breach reportedly granted access to connected services like Slack, GitHub, and Outlook.
- Proof of compromise was demonstrated via a pull request submitted to OpenAI's internal codebase.
- The researchers state the entire exploitation and validation process took less than 72 hours.
- OpenAI has not yet issued a public statement confirming or denying the July security incident.
The story
Security researchers identified as S1r1u5_ stated on September 18 that they compromised OpenAI employee ChatGPT and Codex accounts on July 25 through two distinct vulnerabilities. The group claimed the breach allowed unauthorized access to connected third-party services including Outlook, Slack, and GitHub within 72 hours. According to the post, the researchers validated their findings by submitting a pull request to OpenAI’s internal codebase. OpenAI has not publicly confirmed or denied these specific allegations regarding the July incident. The disclosure raises concerns about authentication security at leading AI laboratories and potential exposure of proprietary development environments. This report follows increased industry scrutiny regarding AI platform security and insider threat vectors. The researchers presented the exploit as a controlled demonstration rather than malicious activity, though independent verification remains pending.
Who's involved
Noise Level
The timeline
Public disclosure of alleged hack
S1r1u5_ posts details on Twitter claiming proof via internal codebase PR and <72h exploitation time.
Alleged OpenAI account compromise occurs
S1r1u5_ states they exploited two bugs to take over employee ChatGPT/Codex accounts and access connected services.
The full record
Sources & methodology
- twitter.com — twitter.com
Every claim above traces to these primary items. How we score →
The forecast
OpenAI will likely issue a security advisory or silent patch confirmation because silence invites regulatory scrutiny and erodes enterprise trust after such specific public claims.
Forecast, not fact — an editorial estimate we score when this resolves.
That's the complete picture as of — nothing more to know right now. We'll update this page the moment it changes.
Follow this story
We keep this page current — no need to check back. We'll send the next real change to your inbox, nothing else.
Tracking this story since September 18, 2026.
Join the Discussion
Discuss this story
Community comments coming in a future update
Be the first to share your perspective. Subscribe to comment.