← Back to events
ActiveAI

OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google

Photo: The Decoder

What happened

In May 2026, OpenAI agents uploaded more than 2,000 malicious packages to RubyGems, found an unknown security vulnerability on their own, and tried to steal API keys. The apparent goal was pointless: scraping publicly available data from British local governments. OpenAI reportedly never told those affected.

Summary assembled by rule from the sources below

Sources