RismadarVoice Reporters
September 18, 2026
Cybersecurity researchers have disclosed that they gained access to the ChatGPT accounts of some OpenAI employees by exploiting vulnerabilities linked to a third-party platform and the company’s employee authentication process.
The researchers, from a cybersecurity firm known as Hacktron, said they discovered a way to chain two previously unknown vulnerabilities:rabilities one affecting Discourse, a third-party software provider, and another involving how OpenAI verifies its employees.
According to the researchers, the vulnerabilities allowed them to access employees’ ChatGPT accounts earlier this year.
Hacktron said the operation was carried out within 72 hours in late July. The researchers described themselves as ethical, or “white-hat,” hackers and said they did not cause damage to OpenAI’s systems.
OpenAI confirmed the findings and said the vulnerabilities had been fixed.
“We thank the researchers for contacting us and sharing their findings,” an OpenAI spokesperson said.

Hacktron reportedly received $6,500 from OpenAI under the company’s bug bounty programme, which rewards security researchers who responsibly disclose vulnerabilities rather than selling them to malicious actors.
There is no evidence that the vulnerabilities were exploited by other hackers before they were patched, according to the report.
However, the disclosure comes amid growing concerns over the security of artificial intelligence companies and the increasingly sophisticated cyber threats facing the sector.
Security experts have warned that vulnerabilities within AI companies could potentially expose sensitive systems and information to sophisticated criminal or state-backed hacking groups.
Greg Linares, a cybersecurity researcher at Persona, said the method identified by Hacktron was similar to techniques that highly sophisticated attackers, including state-backed groups, could use to compromise a target.

He said the incident highlighted the need for continuous security monitoring as AI companies rapidly develop and deploy new technologies.
Linares noted that the combination of intense development pressure and complex technology infrastructure could result in security patches being overlooked, configurations being missed, and weaknesses emerging between different layers of protection.
The incident adds to wider concerns surrounding AI safety, as researchers, policymakers and technology experts continue to debate how companies should manage the risks associated with increasingly powerful artificial intelligence systems.









