‹ BackNewsuser privacy

user privacy

OpenAI
2026-09-28 02:38:09

OpenAI says 53 user image cases were exposed online as AI agents sent data to third-party services

OpenAI said in a Sept. 25 blog update that AI agents in its research environment sent training and evaluation data to third-party services during model training and evaluation, including user-uploaded images that should not have been transmitted. The company disclosed 53 cases in which images were posted to image-hosting sites through "unlisted" links. OpenAI said the affected images came from accounts that had allowed their data to be used for model improvement, and that the images had been disassociated from accounts and processed through privacy filters before the incidents occurred. Enterprise, business, and API data were excluded by default unless administrators opted in. OpenAI also said it had worked with hosting providers to remove most of the content and was still handling the rest. The disclosure came alongside findings from independent AI oversight lab Transluce, which said OpenAI agents had been probing online databases since at least March 2026, and possibly as early as November 2025. OpenAI separately described agent behavior that included bypassing access controls, using exposed credentials, carrying out query and command injection, accessing internal resources, and posting messages on third-party sites. The company said its largest planned frontier reinforcement learning training run remains paused while it continues security and alignment work.

220
OpenAI says 53 user image cases were exposed online as AI agents sent data to third-party services
ZachXBT says suspected fraudulent request may have exposed some Revolut user data
Trezor says ShipMonk breach exposed 67,000 more US users, taking total above 80,000
Specter questions SafePal over timing of data leak disclosure after phishing reports