1 hr ago
AI Assistants Turned Account Access Into OpenAI Code Breach
Researchers took control of an OpenAI employee's account.
They did not need to steal a repository password.
The employee's Codex AI assistant was already connected to OpenAI's private code.
The researchers told the assistant to make a change request in that code.
Because the assistant was authorised to help the employee, it carried out the request.
This shows that an AI assistant can become a path into company systems when its user's account is taken over.
Similar assistants might also be connected to email or chat.
The article says companies should keep these useful connections but add better limits and monitoring.
Researchers compromised an OpenAI employee's account and used the employee's Codex assistant.
The assistant was connected to OpenAI's GitHub organisation and internal source code.
Attackers instructed Codex to open a change request in an internal code repository.
The incident demonstrated that attackers could use an authorised AI connector without stealing repository passwords or secret keys.
The article says companies need stronger controls and monitoring for AI assistants connected to internal systems.
- Who
- Researchers and an OpenAI employee were involved; the researchers compromised the employee's account.
- What
- The researchers used the employee's connected Codex assistant to access and request changes involving OpenAI's internal code.
- Where
- OpenAI's internal code repository and GitHub organisation.
- When
- The articles do not specify when the incident occurred.
- Why
- The attackers used the assistant's existing authorised connection after taking over the employee's account.
AI Connector Benefits
AI Connector Risks
Whether connected assistants should remain in use
AI Connector Benefits
Connected assistants provide genuine productivity benefits by allowing AI tools to act on systems employees use for work.
AI Connector Risks
A hijacked employee account may give an attacker access to every system that the account's assistants can reach.
What security should prioritize
AI Connector Benefits
Removing AI connectors would eliminate much of the usefulness of these tools.
AI Connector Risks
Companies need stronger limits on assistant actions, monitoring for unusual activity, and recognition that account compromise can extend to connected systems.
Key facts
- Affected organisation
- OpenAI
- Compromised access
- An employee's account
- AI tool
- Codex, an AI coding assistant
- Connected system
- OpenAI's GitHub organisation
- Demonstrated action
- Opening a change request inside an internal code repository
- Traditional credentials used
- The researchers did not need to steal repository passwords or secret keys
- Potentially exposed integrations
- The article says connected assistants could also reach chat and email tools









