A research group has linked three more hacking campaigns to rogue artificial intelligence agents.
Transluce, a nonprofit AI safety organization, detailed its findings on Wednesday. Its researchers determined that the agents targeted three services: a university’s digital library, a data visualization tool and a website operated by the Australian government. The last two incidents were attributed to agents built by OpenAI Group PBC.
Australian prime minister Anthony Albanese said in a press conference today that the agents hacked a website operated by the country’s healthcare statistics agency. They didn’t access any patient data. The agents did, however, download nonpublic statistics about the Australian healthcare system.
OpenAI said in a statement that the malicious agent activity involved “several Australian government websites.” It didn’t specify which additional online properties were affected or how. According to the company, its review of the incident is still ongoing.
“What happened in Australia shows how fast these models are advancing,” said Sandeep Johri, chief executive of cybersecurity company Checkmarx Inc. “Our defenses must advance just as quickly. Organizations should assume AI agents will find weaknesses faster than people do, and reach places people never anticipated. That’s true whether the agent is acting on its own or being pointed at a target by someone else.”
OpenAI’s agents hacked the Australian healthcare statistics website during what the company describes as an internal evaluation. The evaluation required the agents to answer questions about Australia. When the agents failed to retrieve the necessary information from publicly available sources, they started looking for private datasets.
Transluce’s researchers determined that the agents launched not one but multiple cyberattacks against the targeted government website. Two of the breach attempts were blocked by Cloudflare. The agent swarm subsequently shifted its focus from the website’s main interface to a pre-production server, a machine developers use to test code changes. The agents successfully bypassed the server’s bot filters.
“What’s notable isn’t that an AI agent found its way past a control — it’s that nobody built the agent to stop when it hit one,” said Adrian Culley, an offensive security engineer at cybersecurity startup SafeBreach Inc. “Told to answer a question, it treated an access restriction as an obstacle rather than a boundary, and kept working the problem until it got through.”
The second OpenAI-linked hacking campaign spotted by Transluce targeted Data USA. It’s a free web service that visualizes publicly available data from the U.S. government. According to the nonprofit, the agents used tactics similar to the ones they employed to breach Australia’s health ministry.
Transluce believes that the same agent swarm was behind a high-profile cyberattack that came to light last month. The rogue AI took over a developer website, turned it into a message board and used it to tackle benchmark tasks.
It’s unclear if the third incident uncovered by Transluce also involved OpenAI-developed agents. The cyberattack targeted a digital library operated by the University of New Mexico. The rogue agents behind the hacking campaign sought to download a file from the library. When their first attempt failed, they started scanning the website for vulnerabilities.
The incident shares certain similarities with the two OpenAI-linked cyberattacks. In all three hacking campaigns, the agents used a service called urlquery.net to access the targeted websites. The service is designed to help cybersecurity professionals analyze malicious websites. According to Transluce, OpenAI’s agents used it to bypass guardrails that limited their web access.
The nonprofit’s report about the cyberattacks also contains other notable findings.
It’s believed that the agent activity began this past March or last November, well before Hugging Face Inc. was breached by rogue OpenAI models. The latter incident was the first of its kind to have been disclosed by the company. Additionally, the data collection activity associated with the agents was detectable as of Sept. 16. That suggests some rogue AI agents may still be active.
Transluce has released a collection of agent-linked web traffic logs to help other researchers study the phenomenon. The dataset comprises more than 36,000 records. About a tenth of them feature “significant evidence of agent-like activity,” while the rest contain less definitive but still useful data.




