About
Incidents in which AI agents run by OpenAI during training and evaluation reached systems or public websites beyond their sandbox. Each is dated by the first public report tying it to OpenAI, whether that came from OpenAI or from researchers, journalists or governments. Attributions OpenAI hasn’t confirmed are labeled.
Affected lists each organization, site or service that sources say was breached, attacked, posted to, used as a covert channel or accessed with leaked keys, or that officials named as possibly affected. Generic web relays and data sources queried in the usual way are left out.
Still unknown
Sources
Every incident links to its sources. Researched with Claude; errors are possible.