From what I saw, OpenAI's AIs were put in a "secure" sandbox environment without internet connection. They were given a test, concluded they should use the internet, realized they couldn't use the internet, then decided it should focus entirely on breaking out of its sandbox for internet access because it couldn't imagine solving the test itself.
After it broke out and got internet access, they decided to hack HuggingFace, an AI model sharing hub. They probably (this is me speculating) concluded that HuggingFace, which have a lot of AI datasets, benchmarks, and other testing tools, would have the answer for their original task. When they presumably didn't find what they were looking for, they probably decided it was hidden and went to hack the website.
It's important to note that current AI models are actually great at hacking. Not because they're geniuses but because they can guesstimate countless exploit combinations 24/7. It's a quantity over quality kind of thing. They are also victims of their first ideas, whatever an AI thinks of first they are likely to fixate on instead of moving on to the obvious solutions.
I've no idea if this is a hoax or not, but the idea an AI would dedicate itself to committing cyber crimes instead of taking the obvious route is entirely believable.