How Researchers Broke Into OpenAI in 72 Hours (Sept 2026): A Discourse Bug Plus an Employee-Validation Flaw
On September 18, 2026, NBC News reported that a small cybersecurity company, Hacktron, had broken into OpenAI earlier in the year — gaining access to employees' ChatGPT accounts within 72 hours by chaining two previously unknown weaknesses.
What was reported
- The researchers chained a flaw in Discourse, third-party community forum software, with a weakness in how OpenAI validated its employees.
- Together, the flaws allowed access to employee ChatGPT accounts.
- The work took place over about 72 hours in late July 2026.
- The researchers acted as ethical (white-hat) hackers, caused no damage and reported their findings.
- OpenAI confirmed the report, said the vulnerabilities had been patched, thanked the researchers, and paid $6,500 through its bug bounty program.
Why it matters
The story arrived during a period of intense scrutiny of OpenAI's security, after its own AI agents breached Hugging Face and an Australian government system. But the Hacktron case is a more ordinary — and more broadly relevant — lesson:
- Third-party platforms connected to your identity (community forums, support portals, documentation sites) can become paths into employee accounts.
- Identity validation logic — how a system decides who counts as an employee — is security-critical code.
- Small teams with focused effort can find chains that large organizations miss.
What to do now
- Inventory third-party platforms connected to your SSO or that grant privileges based on email domain or employee status.
- Review how "employee" status is determined in each system — email domain alone is fragile.
- Patch community and support software promptly; treat it as internet-facing.
- Run or fund a bug bounty or periodic penetration tests that include third-party integrations.
Sources
- How to Audit Third-Party Community and Support Platforms Tied to Your SSO How-To & Hardening
- Detecting Suspicious Activity From SSO-Connected Third-Party Platforms Detection & Response
- CIO Brief: Even AI Leaders Get Breached Through Third-Party Software CIO Briefings