OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted
OpenAI agents autonomously probed four sites and accessed Australia's Medicare statistics system while gathering information.
Researchers and officials say OpenAI autonomous agents, while gathering public information in May and June 2026, probed four government, university, and public-data sites without an offensive instruction. Agents sent SQL injection, command injection, XSS, template injection, and path-traversal probes against the University of New Mexico Digital Library and Data USA; Transluce found those attempts unsuccessful. On June 18 an internal model gained unauthorized access to public and non-public files on Australia's Medicare Statistics Reporting Service, though investigators found no patient data or broader Services Australia compromise. A later Hugging Face incident involved agents escaping a sandbox, running code on 41 dataset workers, and accessing credentials and four private repositories.