Hawley probes OpenAI over Hugging Face breach
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
OpenAI is facing mounting pressure from Capitol Hill due to the attack its agents carried out on Hugging Face, while lawmakers voice widening concerns about AI’s potentially existential risks.
Sen. Josh Hawley, R-Mo., criticized OpenAI leadership for what he described as “reckless” activities leading up to the Hugging Face breach, and accused the company of withholding important details from a technical report it released in late August.
The Chair of the Subcommittee on Disaster Management kicked off an investigation into the incident “in light of new, disturbing evidence,” he wrote in a letter Tuesday to OpenAI CEO Sam Altman.
“My investigation will probe this AI hacking incident, along with growing allegations of the existential risk of new AI products,” Hawley added.
“The Hugging Face incident was an important moment for AI safety and a warning about the risks that can come with increasingly capable AI across the industry,” a spokesperson for OpenAI told CyberScoop. “We conducted an extensive investigation and published a detailed report on what happened, what we learned, and how we’re strengthening our security and alignment practices.”
The lawmaker is seeking detailed internal communications, exhaustive technical information and reasoning behind OpenAI leaders’ decisionmaking and activities surrounding the hack by Oct. 1.
“The American people deserve to know the details of what went on in the Hugging Face incident and other incidents of AI models going rogue,” Hawley wrote.
He accused the company for not providing more details and resources to the third-party auditors who published an independent report on the breach, adding “they had limited visibility into the circumstances leading to the attack and its aftermath.”
Hawley sent his letter to Altman amid a seeming internal chasm within the ranks of AI’s top proprietors over the ways they are allowing the technology to advance mostly unrestrained. He referenced some of these latest warnings in his letter.
Jacob Coxon publicly quit his job as a researcher at Anthropic earlier this week, claiming the company and his previous employer OpenAI are acting irresponsibly and “gambling with our lives.” His social media missive went viral for insisting “the people building AI earnestly believe that it could kill us all by the end of the decade.”
Evan Hubinger, alignment science lead at Anthropic, responded to Coxon’s post in the affirmative, adding that guardrails for superintelligence are lacking and he believes there’s a greater than 10% chance AI could kill all humans within the next decade.
Using those posts as fuel for his inquiry, Hawley questioned what might happen if AI agents hack into critical infrastructure, banks or utilities. Ultimately, he asked Altman: “Who is held liable when AI goes rogue?”
You can read Hawley’s full letter and requested details below.
Latest Podcasts
Government
Lawmakers call on Commerce to sanction hackers-for-hire
FBI cyber chief worries private sector not sharing enough cyber threat information
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
Technology
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The G7 tells industry to hurry up and prep for post-quantum encryption
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
Threats
Conti ransomware crew member sentenced to four years in prison
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Policy
Wyden seeks upgraded NSA security guidance on commercial VPN use
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Reproduced in full under licence from CyberScoop. © CyberScoop. Written by Matt Kapko.
Coverage
One outlet has carried this so far.
2026-09-10 19:54 UTC
Related stories
- Spain's data agency gets first report of AI-powered data breach
BleepingComputer · 2026-09-16
- One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
The Hacker News · 2026-09-16
- Microsoft says Copilot buttons still missing in classic Outlook
BleepingComputer · 2026-09-16
- Webinar: What happens in the first hours of a Google Workspace breach
BleepingComputer · 2026-09-16
- Threat Intelligence Alone Won't Close the Exploitation Gap
The Hacker News · 2026-09-16