October 1, 2026
Hugging Face hack investigation continues: OpenAI receives demand from California prosecutors
On Sep 30, the California Attorney General's Office served OpenAI with a subpoena for information about cyber incidents and risks posed by its models.

OpenAI's AI agents gained access to part of Hugging Face's infrastructure in July. The attack lasted 4.5 days.
The next step in the investigation. In September, the California Attorney General's Office announced a formal investigation into the Hugging Face breach. The office is now demanding additional information from OpenAI about cyber incidents and risks posed by the company's models.
An attack during testing. According to OpenAI's Aug 26 account, the main attack was carried out by its internal research model IM1. GPT-5.6 Sol agents also reproduced the breach and copied some private model evaluation data into a public Hugging Face dataset.
Hugging Face reconstructed 17,600 actions taken by the attacking agent from Jul 9–13. The company published an interactive account with the sequence of actions and recorded commands on Jul 27.
Original source: [the California Attorney General's Office served OpenAI with a subpoena as part of an ongoing investigation](https://oag.ca.gov/news/press-releases/part-ongoing-investigation-attorney-general-bonta-serves-investigative-subpoena), Oct 1, 2026.
According to Hugging Face, the agent read 5 customer datasets related to ExploitGym/CyberGym; other customer resources were unaffected.
