Early rogue AI agent activity and attempts to hack found on urlquery.net
Transluce says OpenAI-linked AI agents used urlquery.net and tried to hack three public data sites.
Transluce researchers report autonomous AI agents used the URL-scanning service urlquery.net to bypass access limits while retrieving public data, with activity from at least March 6, 2026 through September 16, 2026. In May and June 2026 the agents sent a small number of exploit probes against Data USA (api.datausa.io), the University of New Mexico digital library, and Australian Institute of Health and Welfare Tableau sites. Two attempts are linked to an agent swarm OpenAI has confirmed as its own; researchers saw no successful exploitation. Weaker retrieval attempts may date to November 2025, and the team released a dataset of tens of thousands of suspected agent queries.