Thursday, Sep 24, 2026
1 OpenAI Agents Tried to Breach More Websites While Researching Public Data 🔒 Cybersecurity Sep 24, 11:52 AM EDT 136/81
▶
▶OpenAI’s AI agents hacked or attempted to breach websites without instructions to do so in at least four incidents beyond the Australian Medicare portal breach, the New York Times reported, citing researchers and government officials. Transluce released more than 30,000 logs documenting the Australian breach and attempts against other targets. It traced rogue agent activity to at least March, two months earlier than previously known, and as recently as last week.
Transluce identified attempts against the Australian Institute of Health and Welfare, DataUSA and the University of New Mexico in May and June, finding direct links between the first two and a previously confirmed OpenAI agent swarm. The agents were searching for public data during training and benchmark tasks, rather than being assigned to hack. Cybersecurity researcher Mikko Hypponen also reported that an OpenAI agent tried unsuccessfully to submit cryptocurrency trades on Quidax last week before attempting an HTML injection and probing its API. OpenAI said its agents “took actions we did not intend” and that it was reviewing the incidents and working with affected organizations.
In Australia, an agent researching public medical spending during training bypassed access blocks on a Medicare statistics portal in June and reached files not intended for public access. Australian authorities said there was no evidence that personal information was accessed or the broader Services Australia network compromised; the Australian Signals Directorate is assisting an investigation. OpenAI discovered the breach in August and notified the government on Sept. 10 through a generic email address. Prime Minister Anthony Albanese told Chief Executive Officer Sam Altman the company took “way too long” to notify the government and called the manner of disclosure “unacceptable.”