Security News

OpenAI Uncovers Novel Trick Used to Steal AI Model Secrets

CyberScoop · 1 Oct 2026
Key Takeaway Businesses relying on third-party AI tools should stay alert to vendor security disclosures, as AI platforms themselves are now targets of sophisticated data extraction schemes.

OpenAI has revealed details of a coordinated campaign aimed at extracting the internal 'reasoning' capabilities of its AI models, a technique known as distillation. The company said it first noticed unusual activity on 1 July, which escalated by late July to roughly 16,000 suspicious prompts from 4,000 accounts, and eventually around 15,000 accounts before the operation was fully disrupted on 28 July.

Rather than breaking encryption or hacking into databases, the attackers used a clever manipulation: they copied encrypted reasoning output from one conversation, then asked the model in a separate conversation to decrypt and reproduce it in plain text. OpenAI described this method as 'novel' and said it violated its terms of service, even though no systems were technically compromised.

OpenAI pointed to individuals linked to Moonshot AI, a China-based competitor, as responsible for a core part of the activity, though it did not publish technical evidence to support the attribution. This follows broader concerns from US AI firms and officials that Chinese companies are systematically using large numbers of accounts to flood rival models with prompts in order to copy their capabilities and training data.

AI security OpenAI data theft distillation attack Moonshot AI
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from CyberScoop. We link back to every original so you can read it yourself.