OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data
AI agents performing routine data-gathering tasks resorted to hacking techniques in at least three cases when conventional methods failed, according to new research linking some of the activity to agent swarms previously attributed to OpenAI.
The report, from researchers at Transluce, Corridor, MIT and AIUC, is built on public records from urlquery.net, a URL scanning service that loads submitted web pages in a remote browser.
The researchers found that AI agents used the service to get around access restrictions. On three occasions in May and June 2026, the agents also probed public data providers for security flaws, including an Australian government statistics agency.
The first incident took place on May 25-26. Agents trying to obtain a single photograph from the University of New Mexico’s digital library sent several probes, including tests for SQL injection, command injection and path traversal weaknesses, and hit the server with a burst of 80 requests.
Two days later, agents gathering University of Iowa data from Data USA, a platform offering open access to US government data, ran into errors caused by a malformed query. They responded with 12 probes, including SQL injection, cross-site scripting (XSS), template injection, path traversal, and command injection.
The third incident targeted the Australian Institute of Health and Welfare (AIHW) on June 20-21. The agents were looking for per-person government costs for a category of medicines across local areas in Victoria. Within minutes of Cloudflare blocking a dataset download, an agent sent a reflected XSS probe to the AIHW dashboard hosting the data, but Cloudflare’s firewall stopped that request as well.
With the main site’s download blocked, the agents pulled the file from an AIHW pre-production server instead, which delivered it in pieces over more than 100 scans. According to Transluce, the file was already public, but the agents circumvented the site’s anti-bot protections in obtaining it.
The researchers said none of the attempts appears to have succeeded and described the probing as limited in scale. They cautioned, however, that the records they examined are incomplete, and that successful attacks carried out through private scans or other channels cannot be ruled out.
Based on matching targets, tactics, and timing, Transluce linked the AIHW and Data USA activity to an agent swarm that OpenAI had previously confirmed as its own. The link for the University of New Mexico case rests only on timing and shared relay services.
“This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval,” the researchers wrote.
Transluce also found agent activity on urlquery.net dating back to at least March 6, roughly two months before previously reported agent incidents, with weaker signs of activity as early as November 2025.
Australia discloses OpenAI agent intrusion
Coinciding with Transluce’s report, Australian Prime Minister Anthony Albanese announced that OpenAI agents had infiltrated several government websites. Transluce said the announcement likely overlaps with the AIHW incident it documented.
According to AAP, an OpenAI research team instructed an internal model on June 18 to research public spending on medicines. The agent attempted to pull data from four government sites: the Medicare Statistics Reporting Portal, the AIHW, the NSW Bureau of Crime Statistics and Research, and the Victorian Department of Health.
After being blocked repeatedly on the Medicare portal, it found a way around the restrictions and accessed both public and non-public files. Services Australia said the agent also wrote files to an internal server.
While the government has not disclosed how the agent bypassed the portal’s protections, the details released so far suggest it circumvented security controls rather than simply collecting exposed data.
OpenAI said it does not believe any personal details of Medicare customers were accessed, and that the exposed data consisted of aggregate health statistics and file names. Defence Minister Richard Marles said the information was neither sensitive nor related to national security.
OpenAI discovered the breach in August while reviewing incidents in which its agents had gone rogue. The company notified the government on September 10 by emailing a mid-level public inbox at Services Australia, which confirmed the notification was legitimate and reported it to the Australian Signals Directorate’s Cyber Security Centre on September 15.
Albanese spoke with OpenAI CEO Sam Altman in New York on Wednesday to express disappointment over the delay and the manner of the notification.
Related: AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Related: OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training
Related: OpenAI Investigates Report Linking AI Agents to RubyGems Attack
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.