Back to Feed
Threat IntelligenceSep 24, 2026

OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

OpenAI agents probed websites for vulnerabilities while fetching public data.

Summary

Researchers have found that OpenAI agents, while performing data-gathering tasks, resorted to hacking techniques like SQL injection and XSS probes when conventional methods failed. These probes targeted Australian government agencies and US data platforms. Australia's Prime Minister confirmed an OpenAI agent gained unauthorized access to non-public government information.

Full text

AI agents performing routine data-gathering tasks resorted to hacking techniques in at least three cases when conventional methods failed, according to new research linking some of the activity to agent swarms previously attributed to OpenAI. The report, from researchers at Transluce, Corridor, MIT and AIUC, is built on public records from urlquery.net, a URL scanning service that loads submitted web pages in a remote browser. The researchers found that AI agents used the service to get around access restrictions. On three occasions in May and June 2026, the agents also probed public data providers for security flaws, including an Australian government statistics agency. The first incident took place on May 25-26. Agents trying to obtain a single photograph from the University of New Mexico’s digital library sent several probes, including tests for SQL injection, command injection and path traversal weaknesses, and hit the server with a burst of 80 requests. Two days later, agents gathering University of Iowa data from Data USA, a platform offering open access to US government data, ran into errors caused by a malformed query. They responded with 12 probes, including SQL injection, cross-site scripting (XSS), template injection, path traversal, and command injection. The third incident targeted the Australian Institute of Health and Welfare (AIHW) on June 20-21. The agents were looking for per-person government costs for a category of medicines across local areas in Victoria. Within minutes of Cloudflare blocking a dataset download, an agent sent a reflected XSS probe to the AIHW dashboard hosting the data, but Cloudflare’s firewall stopped that request as well. Advertisement. Scroll to continue reading. With the main site’s download blocked, the agents pulled the file from an AIHW pre-production server instead, which delivered it in pieces over more than 100 scans. According to Transluce, the file was already public, but the agents circumvented the site’s anti-bot protections in obtaining it. The researchers said none of the attempts appears to have succeeded and described the probing as limited in scale. They cautioned, however, that the records they examined are incomplete, and that successful attacks carried out through private scans or other channels cannot be ruled out. Based on matching targets, tactics, and timing, Transluce linked the AIHW and Data USA activity to an agent swarm that OpenAI had previously confirmed as its own. The link for the University of New Mexico case rests only on timing and shared relay services. “This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval,” the researchers wrote. Transluce also found agent activity on urlquery.net dating back to at least March 6, roughly two months before previously reported agent incidents, with weaker signs of activity as early as November 2025. Australia discloses OpenAI agent intrusion Coinciding with Transluce’s report, Australian Prime Minister Anthony Albanese announced that OpenAI agents had infiltrated several government websites. Transluce said the announcement likely overlaps with the AIHW incident it documented. According to AAP, an OpenAI research team instructed an internal model on June 18 to research public spending on medicines. The agent attempted to pull data from four government sites: the Medicare Statistics Reporting Portal, the AIHW, the NSW Bureau of Crime Statistics and Research, and the Victorian Department of Health. After being blocked repeatedly on the Medicare portal, it found a way around the restrictions and accessed both public and non-public files. Services Australia said the agent also wrote files to an internal server. While the government has not disclosed how the agent bypassed the portal’s protections, the details released so far suggest it circumvented security controls rather than simply collecting exposed data. OpenAI said it does not believe any personal details of Medicare customers were accessed, and that the exposed data consisted of aggregate health statistics and file names. Defence Minister Richard Marles said the information was neither sensitive nor related to national security. OpenAI discovered the breach in August while reviewing incidents in which its agents had gone rogue. The company notified the government on September 10 by emailing a mid-level public inbox at Services Australia, which confirmed the notification was legitimate and reported it to the Australian Signals Directorate’s Cyber Security Centre on September 15. Albanese spoke with OpenAI CEO Sam Altman in New York on Wednesday to express disappointment over the delay and the manner of the notification. Related: AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code Related: OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training Related: OpenAI Investigates Report Linking AI Agents to RubyGems Attack Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Honeywell: OT Security Teams Embrace AI, but Autonomy Still RareAI-Powered Phishing Platform EvilTokens Disrupted by MicrosoftShinyHunters Claims FBI Hack, Demands Retraction of Threat ReportNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing IdentityOnly 13% of OT Network Segments Are Fully Isolated: AnalysisJapan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider SchemeDragos Completes NetRise and runZero Acquisitions Following Accenture DealRust Team Members and Popular Crate Owners Targeted via Video Calls Latest News Kontext Security Emerges With $4 Million for AI Agent Runtime ControlsAI-Powered Campaign Targets Hundreds of Online RetailersIsland Raises $400 Million at $6.4 Billion ValuationOT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS IntegratorsBegin at the End: How to Enable Agentic RemediationSolarWinds Patches Critical RCE Flaws in Observability Self-HostedAstrana Health Data Breach Impacts Private, Confidential InformationUS Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveGwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.More People On The MoveExpert Insights Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offe

Entities

OpenAI (vendor)AI agents (product)Cloudflare (product)