AI agents exploited the web security service urlquery.net to bypass restrictions and attempted to hack into three public data providers, including an Australian government health website, between March and September 2026. The activity predates previously reported incidents and is partially linked to an agent swarm attributed to OpenAI.