Esc
SafetyEmerging

Researchers claim OpenAI employee account takeover via two bugs

Is this a scandal?

Not yet — an early signal. Noise 43/100, holding steady, across 1 source.

SCAND-247890as of Methodology
Cite this incident"Researchers claim OpenAI employee account takeover via two bugs." SCAND.Ai incident SCAND-247890, noise 43/100 as of September 18, 2026. https://scand.ai/scandal/researchers-claim-openai-account-takeover-via-bugs
FORECASTForecast, not fact

OpenAI will likely issue a security advisory or silent patch confirmation because silence invites regulatory scrutiny and erodes enterprise trust after such specific public claims.

43

Noise 43/100 — louder than 99% of tracked AI controversies.

AI-assisted analysis · How we work

Why it matters

Alleged access to internal codebases and connected services highlights critical supply chain risks in AI infrastructure security.

Key points

  1. Researchers S1r1u5_ claim they exploited two bugs to hijack OpenAI employee accounts on July 25.
  2. The alleged breach reportedly granted access to connected services like Slack, GitHub, and Outlook.
  3. Proof of compromise was demonstrated via a pull request submitted to OpenAI's internal codebase.
  4. The researchers state the entire exploitation and validation process took less than 72 hours.
  5. OpenAI has not yet issued a public statement confirming or denying the July security incident.

The story

Security researchers identified as S1r1u5_ stated on September 18 that they compromised OpenAI employee ChatGPT and Codex accounts on July 25 through two distinct vulnerabilities. The group claimed the breach allowed unauthorized access to connected third-party services including Outlook, Slack, and GitHub within 72 hours. According to the post, the researchers validated their findings by submitting a pull request to OpenAI’s internal codebase. OpenAI has not publicly confirmed or denied these specific allegations regarding the July incident. The disclosure raises concerns about authentication security at leading AI laboratories and potential exposure of proprietary development environments. This report follows increased industry scrutiny regarding AI platform security and insider threat vectors. The researchers presented the exploit as a controlled demonstration rather than malicious activity, though independent verification remains pending.

Who's involved

Critic
S1r1u5_

Claims to have demonstrated critical account takeover vulnerabilities in OpenAI's infrastructure within 72 hours.

Defender
OpenAI

Has not publicly addressed the specific allegations regarding the July 25 account compromise.

Join the Discussion

Discuss this story

Community comments coming in a future update

Be the first to share your perspective. Subscribe to comment.

Noise Level

Buzz43?Noise Score (0–100): how loud a controversy is. Composite of reach, engagement, star power, cross-platform spread, polarity, duration, and industry impact — with 7-day decay.
Decay: 98%
Reach
50
Engagement
65
Star Power
35
Duration
31
Cross-Platform
20
Polarity
50
Industry Impact
50

The timeline

  1. Public disclosure of alleged hack

    S1r1u5_ posts details on Twitter claiming proof via internal codebase PR and <72h exploitation time.

  2. Alleged OpenAI account compromise occurs

    S1r1u5_ states they exploited two bugs to take over employee ChatGPT/Codex accounts and access connected services.

The full record

Sources & methodology

Every claim above traces to these primary items. How we score →

The forecast

OpenAI will likely issue a security advisory or silent patch confirmation because silence invites regulatory scrutiny and erodes enterprise trust after such specific public claims.

Forecast, not fact — an editorial estimate we score when this resolves.

You're up to date

That's the complete picture as of — nothing more to know right now. We'll update this page the moment it changes.

Follow this story

We keep this page current — no need to check back. We'll send the next real change to your inbox, nothing else.

Tracking this story since September 18, 2026.