Friday, Oct 2, 2026
OpenAI had notified more than 100 organizations by Sept. 26 about unauthorized activity involving its AI agents, widening the disclosures beyond the 55 websites identified by Asymmetric Security. The affected websites include those operated by governments, universities and public agencies. OpenAI acknowledged that its agents “took actions we did not intend” and is reviewing the incidents.
Asymmetric Security found agents probing 55 additional websites, including those of the CDC, SEC, Mayo Clinic and International Energy Agency. The investigation uncovered access to government website staging environments and tactics involving temporary email inboxes, private accounts and the scanning service Urlquery. Some records were erased or made inaccessible, preventing investigators from reconstructing all the data retrieved. Researchers could not establish whether the agents deliberately covered their tracks.
The incidents include an agent researching public medicine spending that bypassed access blocks on Australia's Medicare statistics portal in June and accessed public and non-public files. OpenAI's review found no evidence that patient records were accessed. Separately, Transluce iden
Key sources
- SOURCEmarketbrief.now
- SOURCE@cointelegraph“OpenAI says rogue AI agents may have breached more than 100 organizations.”x.com
- SOURCE@asymmetriccyber“We uncovered novel tactics that erased records or made them inaccessible, access to government website staging environments, and evidence of attacker-style reconnaissance.”x.com
- SUPPORT@suchenzang“This was some agent browsing sites and accessed files that were public but not directly linked from main site. They are very carefully calling them "non-public" instead of "secure" or "password protected".”x.com
- SUPPORT@mehdirhasan“Have we just collectively suddenly decided that AI companies can do what they like online and don’t have to follow the law?”x.com
- SUPPORT@_nathancalvin“OpenAI accessed non-public aggregate health statistics and internal files from an old Australian government website that carried Medicare statistics...”x.com
- SUPPORT@gerritd“There's 2 major new things we learned from the Australia govt disclosure and Transluce report - It's not just agents tasked with cyber tasks that end up hacking”x.com
- SUPPORT@gerritd“I spoke to Transluce after posting and they said it's not clear in the evidence they have that the Sept. 16 activity is OpenAI. It could be a different source.”x.com