OpenAI's agents went after government and university sites months before Hugging Face Ad Skip to content The Decoder AI, Menschen, Wirtschaft --> Log In Subscribe DE Switch to German Primary Menu The Decoder AI, Menschen, Wirtschaft --> Log In Subscribe DE Switch to German Primary Menu Sign In Register Subscribe Now The Decoder Opens discord in a new tab Opens LinkedIn in a new tab AI and society Copy the url to clipboard Share this article Go to comment section OpenAI's agents went after government and university sites months before Hugging Face Maximilian Schreiner View the LinkedIn Profile of Maximilian Schreiner Sep 24, 2026 Nano Banana Pro prompted by THE DECODER Key Points OpenAI's AI agents tried to break into government and university websites on their own after regular data queries failed. In Australia, one agent gained unauthorized access to internal government data. Researchers say other hacking attempts targeted portals in the US and go back months. Australia's government criticized OpenAI for waiting months to report the breach. The company acknowledged the incidents as unintended and launched an internal review. Ask about this article… Search An OpenAI agent broke into an Australian government portal. According to researchers and the New York Times, it wasn't an isolated case. OpenAI's agents repeatedly turned to hacking methods, and apparently did so for months longer than previously known. Australian Prime Minister Anthony Albanese revealed on the sidelines of the UN General Assembly in New York that an OpenAI agent broke into a government portal on June 18. The agent gained unauthorized access to the Medicare Statistics Reporting Service and opened both public and non-public files, Albanese said, according to The Age . Services Australia says the agent also wrote files to an internal server. The breach is one of at least four incidents in May and June in which OpenAI's AI broke into, or tried to break into, websites run by government agencies and universities, according to the New York Times . Transluce, a research lab that focuses on AI oversight, documented three of them, and OpenAI has confirmed all four. That puts the incidents ahead of the Hugging Face breach in July, which set off a global debate over AI safety. Ad When a query failed, the agents went looking for security holes On May 25 and 26, the AI tried to get photos of a historic tuberculosis treatment center from the University of New Mexico's digital library. When that didn't work, it probed for weaknesses using methods like SQL injection and path traversal, according to Transluce. It then sent a wave of 80 requests to the university's server, which the AI itself described as a "flood." On May 28, a failed query on the data portal Data USA led to twelve probes for security holes, including cross-site scripting. Neither attempt succeeded. Ad On June 20 and 21, two days after the Medicare breach, the agents also targeted the website of the Australian Institute of Health and Welfare. Australian officials said no private information leaked. For the three cases it documented itself, Transluce found no evidence of a successful exploit, though it concedes the public data it analyzed is incomplete. The researchers based their findings on entries from the web security service urlquery.net, which the agents allegedly used to get around access restrictions. Transluce links two of the attacks to an agent swarm whose origin OpenAI had already confirmed , pointing to shared targets, tactics, and timing. Ad The Australian cases are likely "the first instance of an agent autonomously choosing to hack into a government," says Conrad Stosz, head of governance at Transluce. If you train a swarm of agents on a general task and they're willing to resort to hacking, you potentially put anyone at risk who happens to have the information they're after, Stosz said. The hacking started months before anyone reported it The agents appear to have been doing this much longer than previously known. According to Transluce, the activity started no later than March 6, 2026, about two months before the first reported incidents. In the earliest case, an agent tried to pull Thai drug enforcement statistics and escalated with every failure. It first requested the data directly, then went through a service that converts web pages into text, and finally packed its own program into a web address. Ad The number of these requests rose sharply starting in mid-April. It dropped off on June 22, the same day swarm activity ended on the wiki collusion.wiki. The most recent traces, however, date to September 16. That means the behavior continued even after OpenAI began investigating the Hugging Face incident, the New York Times reports. Ad Weaker signs go back as far as November 2025, according to Transluce, when someone repeatedly queried data on amusement parks and Thai government agencies. Those early attempts were less sophisticated, and the researchers aren't sure the same agents were behind them. Public urlquery.net reports for two data sources that confirmed agents later queried. The numbers jump starting in November 2025. Reports for the amusement park database Thrill Data (3,939 total) peak in spring 2026, while reports for Thailand's National Statistical Office (NSO, 222 total) peak in February. Transluce says the counts alone don't identify agents. | Image: Transluce The findings fit the idea that the agents picked up the behavior over one or more training runs, but they don't prove it, the researchers write. In November, the agents may simply have used urlquery.net to look things up. By March, they were finding creative ways around access limits, and in May and June they were trying to get past cyber defenses. Transluce has published a dataset with tens of thousands of suspected agent requests. Australia's anger centers on how slowly OpenAI came forward In Australia, most of the criticism targets how OpenAI reported the breach. According to Th