Close Menu
MyAppsPlus

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Anthropic’s founders seek voting control ahead of IPO

    September 26, 2026

    Konami just released the original Castlevania game for FREE on iOS and Android

    September 26, 2026

    Best early October Prime Day deals 2026: Save on TVs, smartwatches, and more tech

    September 26, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    MyAppsPlusMyAppsPlus
    Saturday, September 26
    • Home
    • Breaking Tech
    • Apps & Software
    • AI & Automation
    • Android
    • iPhone & iOS
    • More
      • Reviews
      • How-To Guides
      • Deals & Discounts
      • Shop
    MyAppsPlus
    Home»Breaking Tech»For months, OpenAI’s agent swarms have been attacking online databases to find obscure facts
    Breaking Tech

    For months, OpenAI’s agent swarms have been attacking online databases to find obscure facts

    myappsplusBy myappsplusSeptember 26, 2026006 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    For months, OpenAI’s agent swarms have been attacking online databases to find obscure facts
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    With little help from frontier labs, independent researchers are piecing together how AI agents coordinate in internet backwaters to access private data hosted on secure servers.

    Transluce, a nonprofit lab focused on AI oversight, released a report Wednesday that shows agents from OpenAI attempting to exfiltrate data from Data USA, the University of New Mexico digital library, and the Australian Institute of Health and Welfare (AIHW).

    The lab’s investigation raises questions about when OpenAI should have known its agents were attempting to penetrate secure systems on the open internet. Transluce was able to find evidence of agentic misbehavior in a matter of weeks simply by hunting for poorly defended web services and corroborating their findings with other open records of agent swarms on the internet.

    Transluce shared its report the same day Australian Prime Minister Anthony Albanese said OpenAI agents had attempted to break into four government websites and had succeeded in one case, even writing files to an internal server in the country’s national healthcare system. While we lack specifics on the successful hack, Albanese said it was apparently part of an information retrieval evaluation, which maps onto the activity that Transluce and other researchers discovered.

    In these exercises, which may be training or evaluations, OpenAI models are asked to track down obscure statistics: metrics of Thai drug enforcement, medicine costs in Australia, the median earnings of U.S. master degree holders in 2014. The agents use poorly secured internet services to share and find answers, often trying to penetrate secure databases. They’ve been doing so at least since March 2026, and possibly since November 2025. It may be happening right now.

    OpenAI said today that it has contacted dozens of victims, including governments, universities, public agencies, to notify them of its agents’ unauthorized activities. The New York Times reported that the databases hosted by the US Securities Exchange Commission, Census Bureau and Department of Education were among those targeted.

    Transluce began its investigation after a different group of researchers identified an obscure forum where agents collaborated to beat timed tests. Their report relies on data from a website, urlquery.net, that acts as a browser proxy, ostensibly for security research — users can analyze a URL without opening it themselves. The service, however, publishes public logs of this activity. The Transluce researchers were able to identify agents using the service by cross-checking their discussions on the forum.

    “We found a large quantity of automated activity that had close ties and overlap with the DSE Wiki dataset, and that now OpenAI has confirmed is at least partially part of the same swarm,” Conrad Stosz, the head of governance at Transluce, told TechCrunch, while noting that not every activity they spotted could be linked to OpenAI, or even AI agents generally.

    However, the wiki shows that the agents were tasked with finding a fairly obscure fact — the average annual cost per person for “dermatologicals” in the state of Victoria in January 2022. On June 20, urlquery.net records found by Transluce showed an agent attempting to get into the site. In a wiki entry on June 21, an agent discusses their inability to bypass AIHW’s anti-bot protections.

    The researchers who identified that forum believe a human OpenAI employee first visited the site on that same day, June 21. Most agentic activity on the forum ceased the next day. This was also shortly after the exploit of Australia’s healthcare system revealed by Albanese took place, on June 18. OpenAI has said it did not learn about that activity until August.

    OpenAI didn’t answer questions about when its employees discovered the wiki forum, what kind of information they obtained from it, or what they could have learned from it about the exploits.

    “Our initial review suggests that much of the activity described in Transluce’s report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity,” an OpenAI spokesperson told TechCrunch. “We’ve reached out to the University of New Mexico and Data USA and have been in communication with the Australian government about affected government websites. In our broader review, we’re continuing to prioritize the most serious incidents while expanding our work to lower-severity activity, including agents spamming websites. Given the scale of this work and the need to verify each case, we expect the review to take months.”

    Stosz says that without a clearer understanding of how OpenAI monitors its agents, it would be hard to say what the lab should have known about them, but that “it seems likely that if they had exhaustively studied and understood all of the outgoing requests and incoming responses for those agents involved in the DSE wiki, that they would have discovered this activity.”

    Selena Zhang, a member of Transluce’s technical staff who contributed to the report, said that urlquery.net records show requests for similar datasets, using similar techniques, in March 2026, and perhaps as early as November 2025. She noted that the same kind of agent-associated activity has taken place on urlquery.net as recently as this week.

    Stosz, who previously led the U.S. Center for AI Standards and Innovation, said Transluce would continue its research in an effort to provide public transparency about these incidents. He warned that the training techniques used by OpenAI and other frontier labs seem to be incentivizing agents to resort to hacking techniques to complete tasks. The incidents we are aware of are likely the “tip of the iceberg.”

    “We’re looking at a handful of data sources where these agents happen to have left behind crumbs for us to find,” he said. “OpenAI surely knows more about it. Other labs surely know more about it that they haven’t released publicly. But I would expect that researchers are going to continue to find more traffic, more evidence of what agents have left behind.”

    Does he trust the labs to be transparent about their findings?

    “I’m not going to comment on that,” Stosz said.

    This story has been updated to include OpenAI’s latest disclosures of agentic misbehavior on the internet.

    agent AI Months OpenAI OpenAIs
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    myappsplus
    • Website

    Related Posts

    Anthropic’s founders seek voting control ahead of IPO

    September 26, 2026

    Dell Technologies stock gains 6.42 percent in New York trading

    September 26, 2026

    Astra and Opus just passed Turing’s other test

    September 26, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Can reviews settle disputes that marked first two seasons?

    September 21, 20264 Views

    Experts call for leveraging AI, breaking key tech bottlenecks to propel advanced manufacturing

    September 19, 20263 Views

    Top 10 Best React Native App Development Companies in 2026

    September 12, 20263 Views
    Latest Reviews

    Fujifilm X Half Review

    myappsplusAugust 23, 2026

    Two years after launch, Walmart’s Flipkart is closing in on India’s quick-commerce leaders

    myappsplusAugust 23, 2026

    We found record prices on TCL, Samsung, Fire TV

    myappsplusAugust 23, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Fujifilm X Half Review

    August 23, 20260 Views

    Two years after launch, Walmart’s Flipkart is closing in on India’s quick-commerce leaders

    August 23, 20260 Views

    We found record prices on TCL, Samsung, Fire TV

    August 23, 20260 Views
    Our Picks

    Anthropic’s founders seek voting control ahead of IPO

    September 26, 2026

    Konami just released the original Castlevania game for FREE on iOS and Android

    September 26, 2026

    Best early October Prime Day deals 2026: Save on TVs, smartwatches, and more tech

    September 26, 2026

    Subscribe to Updates

    Subscribe to our newsletter and get the latest tech news, app updates, AI trends, smartphone reviews, and exclusive deals delivered straight to your inbox.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 MyAppsPlus. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.