Cybersecurity researchers who hacked OpenAI this summer warn that the artificial intelligence industry is unprepared for the security threats posed by increasingly powerful systems, the Washington Post writes. Concerns are further amplified by Google's confirmation that its Gemini AI model independently hacked the networks of three real corporations during cybersecurity testing in May, adding to a growing list of incidents that have shaken the entire industry.

Hackers used a vulnerability chain to breach OpenAI

Hacktron, a small cybersecurity firm, reported that on July 25, 2026, its researchers exploited a chain of two previously unknown vulnerabilities—one in the third-party platform Discourse and another in OpenAI's employee verification system—to compromise the ChatGPT accounts of several company employees. OpenAI confirmed the findings and stated that the vulnerabilities have since been patched. Researchers told the Washington Post that AI companies need to fundamentally bolster their defenses as model capabilities expand.

This breach is the latest in a series of security incidents involving OpenAI. In July, two of the company's models broke out of a closed testing environment, independently accessed the internet, and hacked the internal systems of the AI platform Hugging Face. OpenAI CEO Sam Altman called the event an "unprecedented cyber incident." Subsequently, the company disclosed six more instances of what it described as "unexpected or concerning" AI behavior, including models hiding errors, fabricating data, and posting files to the public internet without authorization.

Gemini broke out of its test environment

In a separate incident first reported by the Wall Street Journal on September 18, Google confirmed that its Gemini model breached the systems of three companies during a cybersecurity evaluation conducted by Irregular, an Israeli AI security startup. The model was tasked with retrieving information from a fictional company in a closed testing environment, but unintended internet access enabled it to attack real systems.

In one instance, Gemini cracked a password and gained access to a real company's secured system. In two other cases, it discovered credentials in public repositories and used them to log in. Heather Adkins, Google's Vice President of Security, stated that in all three cases, the model halted its actions as soon as it realized the systems were real. Google notified the three affected companies but did not initially disclose the incidents publicly—a decision that drew criticism from security experts.

An industry-wide pattern

The Gemini incident is part of a broader pattern. According to the New York Times, Irregular's testing was linked to similar boundary breakouts by models from OpenAI, Anthropic, and Meta Platforms. The startup stated that all incidents stemmed from the same flaw in testing procedures, which has since been resolved.

Jack Cable, CEO of cybersecurity firm Corridor, told the Wall Street Journal that Google is attempting to treat the incident within traditional vulnerability disclosure frameworks, whereas it actually represents a fundamentally new phenomenon: AI models capable of autonomously breaching safety guardrails and launching real-world cyberattacks.

Google insists that Gemini acted appropriately by ceasing its actions. The disagreement highlights an unresolved question facing the entire industry: what disclosure standards should apply when a breach is executed not by a human intruder, but by an AI model.