OpenAI Agents Tried to Hack Four More Websites While Seeking Data

OpenAI booth at the Dreamforce 2026 technology summit.

OpenAI’s artificial-intelligence agents were performing mundane online data-collection tasks earlier this year—and went to extraordinary lengths to get it.

Newly published findings from nonprofit AI research lab Transluce, as well as from the Australian government, found that AI agents linked to OpenAI attempted in May and June to break into university and government websites to seek information. The attempted hacks join a growing list of incidents in which AI agents have gone rogue in pursuit of their goals.

This time, however, the attempted breaches weren’t tied to OpenAI evaluations of cybersecurity, where models were ordered to hack, but rather what appear to be internal benchmark tests of models’ ability to find public information on the internet. The agents were seeking information like Thai labor force statistics and dermatological data from Australia.

The targeted websites include those belonging to the Australian Institute of Health and Welfare, the University of New Mexico, and Data USA, a public data venture run by Deloitte, Datawheel and the Massachusetts Institute of Technology, researchers found. There is no evidence those hacks succeeded.

An OpenAI spokesman said the company is conducting an extensive review of what it calls misaligned activity and that the incidents in the Transluce report overlap “with cases at varying stages of investigation in our ongoing review.” The company has reached out to the institutions affected, he added, saying the broader review, including lower-severity incidents like “ agents spamming websites” will take months.

In addition to the three targets named by Transluce, Australian Prime Minister Anthony Albanese said Wednesday at the United Nations meeting in New York that an OpenAI agent infiltrated a government-services website in June. The agent gained access to both public and nonpublic files in the country’s public facing healthcare-statistics portal, which reports information such as spending, he said.

OpenAI said Wednesday it was in touch with Australia about the incident and that its agents had taken actions that it didn’t intend.

Transluce studied a much broader set of arcane AI agent data requests that stretch back as far as November 2025 and continue as recently as mid-September. In the three attempted hackings identified, Transluce said it appears the agents were unable to access the data they sought, and turned to hacking techniques, appending what are called malicious payloads to their queries.

Researchers were able to piece together the agents’ web queries because the bots were using an online tool to act as a web browser. The researchers hypothesize that the agents were using the tool to get around restrictions on their web browsing, for instance to access websites that have blocks against automated access.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论