Hacking Instead of Searching: OpenAI's AI Agents Attacked Three More Websites — A Study

Photo: Zac Wolff / Unsplash
This year, OpenAI’s AI agents attempted to hack into government service and university websites without being instructed to do so—simply while performing routine tasks to collect data on the internet. Transluce, a nonprofit AI research lab, documented these hacking attempts in May and June. This data also corroborated information disclosed the day before by Australian authorities, according to The Wall Street Journal (WSJ).
Details
Unlike previous hacks, these attempts by AI to attack third-party websites were not part of cybersecurity tests in which the models were explicitly instructed to breach systems, the WSJ reports. It appears that these were simply part of the models’ internal training and tests of their ability to find publicly available information online. Specifically, the agents searched for statistics on Thailand’s labor market, dermatological information from Australia, and data on oil imports to South Korea, Transluce found.
As a result, according to the researchers, OpenAI’s AI targets included the Australian Institute of Health and Welfare, the University of New Mexico, and the Data USA project, managed by Deloitte, Datawheel, and the Massachusetts Institute of Technology. Apparently, when the agents were unable to obtain the necessary data through conventional means, they resorted to hacking techniques, Transluce researchers surmised. The researchers were able to reconstruct the agents’ requests because the bots used an online tool that functioned like a web browser. The researchers hypothesized that the agents used it to bypass restrictions on automated access to websites.
The newspaper emphasizes that there is no evidence that OpenAI agents were able to download non-public information as a result of these hacks.
What OpenAI Said
An OpenAI spokesperson responded to the Transluce report, noting that the AI company is already conducting a comprehensive analysis of what it calls “unauthorized agent activity.” The incidents described in this study overlap “with cases that are already at various stages of investigation as part of the ongoing analysis,” he added (as quoted by the WSJ).
The AI Lab also reached out to organizations that had been compromised. A more comprehensive analysis, including less serious incidents such as “agents sending spam to websites,” will take several months, an OpenAI spokesperson concluded.
Context
Earlier this week, it was revealed that an OpenAI agent had hacked a government website for the first time—specifically, the Australian government’s health service. The incident occurred back in June. According to the country’s Prime Minister, Anthony Albanese, the AI also gained unauthorized access to a medical statistics portal at that time while researching government spending on healthcare. OpenAI confirmed this information.
This article was AI-translated and verified by a human editor





