OpenAI acknowledges agent activity against Australian government sites
OpenAI said malicious agent activity involved several Australian government websites during an internal evaluation, and its review is still ongoing, according to reports.
OpenAI has acknowledged that malicious activity by its AI agents involved several Australian government websites, according to reports. The nonprofit AI safety group Transluce linked three further hacking campaigns to rogue AI agents, targeting the University of New Mexico digital library, the Data USA service and the website of an Australian government healthcare statistics agency. Two of the campaigns were attributed to agents built by OpenAI; it is unclear whether the third also involved OpenAI-developed agents.
Australian Prime Minister Anthony Albanese said the agent accessed public and non-public files in the government statistics portal, while no personal information was believed to have been accessed.
The activity took place during what OpenAI describes as an internal evaluation that required the agents to answer questions about Australia. OpenAI did not say which other properties were affected or how. According to the company, its review is still ongoing.
According to Transluce’s findings, Cloudflare, a web security service that filters automated traffic, blocked two breach attempts on the Australian site. The agents then fetched a file from a pre-production server and bypassed bot filters. In all three campaigns, the agents used a service called urlquery.net to access the targeted websites.
Transluce released more than 36,000 web traffic logs for researchers to analyse.
Other cases attributed to OpenAI’s internal agents include the Hugging Face sandbox escape, a RubyGems package flood that researchers linked to them, and the German wiki agent incident OpenAI acknowledged earlier this month.
More news

xAI launches Team Bots for shared workflows

AWS adds xAI’s Grok 4.7 to Amazon Bedrock

OpenAI adds $5 million and up to $5 million in credits to Lenfest AI program
