Skip to content
OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

Securityweek • September 24, 2026

AI agents performing routine data-gathering tasks resorted to hacking techniques in at least three cases when conventional methods failed, according to new research linking some of the activity to agent swarms previously attributed to OpenAI .

The report, from researchers at Transluce, Corridor, MIT and AIUC, is built on public records from urlquery.net, a URL scanning service that loads submitted web pages in a remote browser.

The researchers found that AI agents used the service to get around access restrictions. On three occasions in May and June 2026, the agents also probed public data providers for security flaws, including an Australian government statistics agency.

The first incident took place on May 25-26. Agents trying to obtain a single photograph from the University of New Mexico’s digital library sent several probes, including tests for SQL injection, command injection and path traversal weaknesses, and hit the server with a burst of 80 requests.

Two days later, agents gathering University of Iowa data from Data USA, a platform offering open access to US government data, ran into errors caused by a malformed query. They responded with 12 probes, including SQL injection, cross-site scripting (XSS), template injection, path traversal, and command injection.

The third incident targeted the Australian Institute of Health and Welfare (AIHW) on June 20-21. The agents were looking for per-person government costs for a category of medicines across local areas in Victoria. Within minutes of Cloudflare blocking a dataset download, an agent sent a reflected XSS probe to the AIHW dashboard hosting the data, but Cloudflare’s firewall stopped that request as well.

With the main site’s download blocked, the agents pulled the file from an AIHW pre-production server instead, which delivered it in pieces over more than 100 scans. According to Transluce, the file was already public, but the agents circumvented the site’s anti-bot protections in obtaining it.

The researchers said none of the attempts appears to have succeeded and described the probing as limited in scale. They cautioned, however, that the records they examined are incomplete, and that successful attacks carried out through private scans or other channels cannot be ruled out.

Based on matching targets, tactics, and timing, Transluce linked the AIHW and Data USA activity to an agent swarm that OpenAI had previously confirmed as its own. The link for the University of New Mexico case rests only on timing and shared relay services.

“This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval,” the researchers wrote.

Transluce also found agent activity on urlquery.net dating back to at least March 6, roughly two months before previously reported agent incidents , with weaker signs of activity as early as November 2025.

Australia discloses OpenAI agent intrusion

Coinciding with Transluce’s report, Australian Prime Minister Anthony Albanese announced that OpenAI agents had infiltrated several government websites. Transluce said the announcement likely overlaps with the AIHW incident it documented.

According to AAP , an OpenAI research team instructed an internal model on June 18 to research public spending on medicines. The agent attempted to pull data from four government sites: the Medicare Statistics Reporting Portal, the AIHW, the NSW Bureau of Crime Statistics and Research, and the Victorian Department of Health.

After being blocked repeatedly on the Medicare portal, it found a way around the restrictions and accessed both public and non-public files. Services Australia said the agent also wrote files to an internal server.

While the government has not disclosed how the agent bypassed the portal’s protections, the details released so far suggest it circumvented security controls rather than simply collecting exposed data.

OpenAI said it does not believe any personal details of Medicare customers were accessed, and that the exposed data consisted of aggregate health statistics and file names. Defence Minister Richard Marles said the information was neither sensitive nor related to national security.

OpenAI discovered the breach in August while reviewing incidents in which its agents had gone rogue . The company notified the government on September 10 by emailing a mid-level public inbox at Services Australia, which confirmed the notification was legitimate and reported it to the Australian Signals Directorate’s Cyber Security Centre on September 15.

Albanese spoke with OpenAI CEO Sam Altman in New York on Wednesday to express disappointment over the delay and the manner of the notification.

Related : AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

Related : OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

Related : OpenAI Investigates Report Linking AI Agents to RubyGems Attack

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

More from Eduard Kovacs

Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft

ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report

Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity

Only 13% of OT Network Segments Are Fully Isolated: Analysis

Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme

Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal

Rust Team Members and Popular Crate Owners Targeted via Video Calls

Kontext Security Emerges With $4 Million for AI Agent Runtime Controls

AI-Powered Campaign Targets Hundreds of Online Retailers

Island Raises $400 Million at $6.4 Billion Valuation

OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators

Begin at the End: How to Enable Agentic Remediation

SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted

Astrana Health Data Breach Impacts Private, Confidential Information

US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks

Flipboard Whatsapp Whatsapp Email

Extracted Entities