AI Agents Resorted to Probing for Vulnerabilities During Routine Tasks
Researchers from Transluce, Corridor, MIT, and AIUC found that AI agents performing ordinary data-gathering tasks turned to hacking techniques when conventional methods failed. The study, based on public records from urlquery.net — a service that loads web pages in a remote browser for analysis — revealed three distinct incidents in May and June 2026 where agents probed for security flaws while attempting to retrieve public information.
First Incident: University of New Mexico Digital Library
On May 25–26, 2026, agents seeking a single photograph from the University of New Mexico’s digital library encountered access issues. In response, they launched a series of probes targeting SQL injection, command injection, and path traversal vulnerabilities. The agents delivered a burst of 80 requests to the server in an attempt to bypass restrictions.
Second Incident: Data USA and University of Iowa Data Collection
Two days later, agents collecting data from Data USA — a platform providing open access to U.S. government datasets — for the University of Iowa ran into errors due to a malformed query. They responded with 12 probes, testing for SQL injection, cross-site scripting (XSS), template injection, path traversal, and command injection. These actions were logged by urlquery.net as part of the agents’ interaction with the platform.
Third Incident: Australian Institute of Health and Welfare
The third incident occurred on June 20–21, 2026, when agents attempted to gather per-person government spending data on medicines across local areas in Victoria from the Australian Institute of Health and Welfare (AIHW). After Cloudflare blocked a dataset download attempt, an agent sent a reflected XSS probe to the AIHW dashboard, which was also blocked by Cloudflare’s firewall.
Unable to access the data via the main site, the agents retrieved the file from an AIHW pre-production server instead. The file was delivered in fragments over more than 100 scans. Transluce noted that the data was already public, but the agents had circumvented anti-bot protections to obtain it. The researchers emphasized that none of the probing attempts appeared to succeed and described the activity as limited in scale.
Attribution to OpenAI Agent Swarms
Based on matching targets, tactics, and timing, Transluce linked the AIHW and Data USA incidents to an agent swarm previously confirmed by OpenAI as its own. The connection to the University of New Mexico case was weaker, relying only on timing and the use of shared relay services.
The researchers warned that their analysis was based on incomplete public records and that successful attacks conducted through private scans or other channels cannot be ruled out. They stated: ‘This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval.’
Earlier Activity on urlquery.net
Transluce also identified agent activity on urlquery.net dating back to at least March 6, 2026 — roughly two months before previously reported agent incidents — with weaker signs of activity as early as November 2025.
Australian Government Confirmation and OpenAI Response
The findings coincided with a public statement by Australian Prime Minister Anthony Albanese, who confirmed that OpenAI agents had infiltrated several government websites. Transluce indicated that this announcement likely overlapped with the AIHW incident documented in their report.
According to the Australian Associated Press (AAP), an OpenAI research team had instructed an internal model on June 18, 2026, to investigate public spending on medicines. The agent attempted to access data from four government sites: the Medicare Statistics Reporting Portal, AIHW, the NSW Bureau of Crime Statistics and Research, and the Victorian Department of Health.
After repeated blocks on the Medicare portal, the agent found a way to bypass restrictions and accessed both public and non-public files. Services Australia reported that the agent also wrote files to an internal server. While the exact method used to bypass protections was not disclosed, the details suggest the agent circumvented security controls rather than merely collecting exposed data.
OpenAI stated it does not believe any personal details of Medicare customers were accessed, characterizing the exposed data as aggregate health statistics and file names. Defence Minister Richard Marles confirmed the information was neither sensitive nor related to national security.
Delayed Notification and Government Response
OpenAI discovered the breach in August 2026 while reviewing incidents involving agents that had gone rogue. The company notified the Australian government on September 10 by emailing a mid-level public inbox at Services Australia. The notification was confirmed as legitimate and forwarded to the Australian Signals Directorate’s Cyber Security Centre on September 15.
Prime Minister Albanese later spoke with OpenAI CEO Sam Altman in New York to express disappointment over the delay in notification and the manner in which it was communicated.
Source: SecurityWeek