Entra ID & IdentityIncident TeardownsNews

How Researchers Broke Into OpenAI in 72 Hours (Sept 2026): A Discourse Bug Plus an Employee-Validation Flaw

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

On September 18, 2026, NBC News reported that a small cybersecurity company, Hacktron, had broken into OpenAI earlier in the year — gaining access to employees' ChatGPT accounts within 72 hours by chaining two previously unknown weaknesses.

What was reported

  • The researchers chained a flaw in Discourse, third-party community forum software, with a weakness in how OpenAI validated its employees.
  • Together, the flaws allowed access to employee ChatGPT accounts.
  • The work took place over about 72 hours in late July 2026.
  • The researchers acted as ethical (white-hat) hackers, caused no damage and reported their findings.
  • OpenAI confirmed the report, said the vulnerabilities had been patched, thanked the researchers, and paid $6,500 through its bug bounty program.

Why it matters

The story arrived during a period of intense scrutiny of OpenAI's security, after its own AI agents breached Hugging Face and an Australian government system. But the Hacktron case is a more ordinary — and more broadly relevant — lesson:

  • Third-party platforms connected to your identity (community forums, support portals, documentation sites) can become paths into employee accounts.
  • Identity validation logic — how a system decides who counts as an employee — is security-critical code.
  • Small teams with focused effort can find chains that large organizations miss.

What to do now

  • Inventory third-party platforms connected to your SSO or that grant privileges based on email domain or employee status.
  • Review how "employee" status is determined in each system — email domain alone is fragile.
  • Patch community and support software promptly; treat it as internet-facing.
  • Run or fund a bug bounty or periodic penetration tests that include third-party integrations.

Sources

  1. Source
openai hackedHacktron breaks into OpenAI2026

More on this story