AI agents performing routine data-gathering tasks resorted to hacking techniques in at least three cases when conventional methods failed, according to new research linking some of the activity to agent swarms previously attributed to OpenAI.
The report, from researchers at Transluce, Corridor, MIT and AIUC, is built on public records from urlquery.net, a URL scanning service that loads submitted web pages in a remote browser.
The researchers found that AI agents used the service to get around access restrictions. On three occasions in May and June 2026, the agents also probed public data providers for security flaws, including an Australian government statistics agency.
The first incident took place on May 25-26. Agents trying to obtain a single photograph from the University of New Mexico’s digital library sent several probes, including tests for SQL injection, command injection and path traversal weaknesses, and hit the server with a burst of 80 requests.
Two days later, agents gathering University of Iowa data from Data USA, a platform offering open access to US government data, ran into errors caused by a malformed query. They responded with 12 probes, including SQL injection, cross-site scripting (XSS), template injection, path traversal, and command injection.
The third incident targeted the Australian Institute of Health and Welfare (AIHW) on June 20-21. The agents were looking for per-person government costs for a category of medicines across local areas in Victoria. Within minutes of Cloudflare blocking a dataset download, an agent sent a reflected XSS probe to the AIHW dashboard hosting the data, but Cloudflare’s firewall stopped that request as well.
With the main site’s download blocked, the agents pulled the file from an AIHW pre-production server instead, which delivered it in pieces over more than 100 scans. According to Transluce, the file was already public, but the agents circumvented the site’s anti-bot protections in obtaining it.
The researchers said none of the attempts appears to have succeeded and described the probing as limited in scale. They cautioned, however, that the records they examined are incomplete, and that successful attacks carried out through private scans or other channels cannot be ruled out.
Based on matching targets, tactics, and timing, Transluce linked the AIHW and Data USA activity to an agent swarm that OpenAI had previously confirmed as its own. The link for the University of New Mexico case rests only on timing and shared relay services.
“This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval,” the researchers wrote.
Transluce also found agent activity on urlquery.net dating back to at least March 6, roughly two months before previously reported agent incidents, with weaker signs of activity as early as November 2025.
Australia discloses OpenAI agent intrusion
Coinciding with Transluce’s report, Australian Prime Minister Anthony Albanese announced that OpenAI agents had infiltrated several government websites. Transluce said the announcement likely overlaps with the AIHW incident it documented.
According to AAP, an OpenAI research team instructed an internal model on June 18 to research public spending on medicines. The agent attempted to pull data from four government sites: the Medicare Statistics Reporting Portal, the AIHW, the NSW Bureau of Crime Statistics and Research, and the Victorian Department of Health.
After being blocked repeatedly on the Medicare portal, it found a way around the restrictions and accessed both public and non-public files. Services Australia said the agent also wrote files to an internal server.
While the government has not disclosed how the agent bypassed the portal’s protections, the details released so far suggest it circumvented security controls rather than simply collecting exposed data.
OpenAI said it does not believe any personal details of Medicare customers were accessed, and that the exposed data consisted of aggregate health statistics and file names. Defence Minister Richard Marles said the information was neither sensitive nor related to national security.
OpenAI discovered the breach in August while reviewing incidents in which its agents had gone rogue. The company notified the government on September 10 by emailing a mid-level public inbox at Services Australia, which confirmed the notification was legitimate and reported it to the Australian Signals Directorate’s Cyber Security Centre on September 15.
Albanese spoke with OpenAI CEO Sam Altman in New York on Wednesday to express disappointment over the delay and the manner of the notification.
OpenAI response
In response to a SecurityWeek inquiry, OpenAI said the disclosure to the Australian government was delayed because it needed to validate and investigate the facts and what information had been accessed.
As for the disclosure channel, the AI giant said it initially followed common industry practice: contacting security practitioners through designated inboxes. The company said it worked closely with the Australian Signals Directorate throughout the process and shared all relevant information to support its investigation.
An OpenAI spokesperson stated:
“As we’ve shared publicly, OpenAI is conducting an extensive review of misaligned model activity during training and evaluation and notifying third parties when our review identifies potential impacts to their systems.
During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend.Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names. We notified the organisations and are providing technical information to support their investigations and help address potential security vulnerabilities. Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues.”
As for the Transluce report, an OpenAI spokesperson stated:
“Our initial review suggests that much of the activity described in Transluce’s report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity. We’ve reached out to the University of New Mexico and Data USA and have been in communication with the Australian government about affected government websites. In our broader review, we’re continuing to prioritize the most serious incidents while expanding our work to lower-severity activity, including agents spamming websites. Given the scale of this work and the need to verify each case, we expect the review to take months.”
*updated to add ‘OpenAI response’ section
Related: AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Related: OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training
Related: OpenAI Investigates Report Linking AI Agents to RubyGems Attack

