Entra ID & IdentityCIO BriefingsNews

CIO Brief: Even AI Leaders Get Breached Through Third-Party Software

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

The short version: In September 2026, news broke that a small security firm had broken into OpenAI earlier that year, reaching employees' ChatGPT accounts in 72 hours by combining a flaw in third-party forum software with a weakness in how OpenAI checked who was an employee. The researchers reported it responsibly and were paid a modest bug bounty.

Why this matters to every company

Leading AI companies have significant security resources — and still had a gap in a third-party platform. Most organizations run community forums, support portals and documentation sites connected to employee identities. Each one is a potential path in.

The business impact

  • Account access through peripheral systems.
  • Reputational risk when breaches become public, even if handled responsibly.
  • Opportunity: responsible researchers can find problems before criminals do — if you invite them.

Questions to ask your team

  • Which third-party platforms are connected to our employee sign-in?
  • How does each decide who counts as an employee or administrator?
  • Are those platforms included in our security testing?
  • Do we have a way for outside researchers to report vulnerabilities to us?

What good looks like

An inventory of connected platforms, sign-in through company identity with MFA, privilege based on verified group membership, regular testing, and a vulnerability disclosure or bug bounty program.

The decision

If you don't have a vulnerability disclosure policy, publish one. It's low-cost, and it gives researchers like Hacktron a responsible way to tell you about problems.

Sources

  1. Source
openai hacked impactHacktron breaks into OpenAI2026

More on this story