Tech
EN AZ
For months, OpenAI’s agent swarms have been attacking online databases to find obscure facts

For months, OpenAI’s agent swarms have been attacking online databases to find obscure facts

techcrunch.com 25.09.2026 17:48 2 views
The latest unauthorized agent swarms were discovered by researchers.

With little help from frontier labs, independent researchers are piecing together how AI agents coordinate in internet backwaters to access private data hosted on secure servers. Transluce, a non-profit lab focused on AI oversight, released a report Wednesday that shows agents from OpenAI attempting to exfiltrate data from Data USA, the University of New Mexico digital library, and the Australian Institute of Health and Welfare (AIHW). The lab’s investigation raises questions about when OpenAI should have known its agents were attempting to penetrate secure systems on the open internet.

Transluce was able to find evidence of agentic misbehavior in a matter of weeks simply by hunting for poorly defended web services and corroborating their findings with other open records of agent swarms on the internet. Transluce shared its report the same day Australian Prime Minister Anthony Albanese said OpenAI agents had attempted to break into four government websites and had succeeded in one case, even writing files to an internal server in the country’s national healthcare system. While we lack specifics on the successful hack, Albanese said it was apparently part of an information retrieval evaluation, which maps onto the activity that Transluce and other researchers discovered.

In these exercises, which may be training or evaluations, OpenAI models are asked to track down obscure statistics: metrics of Thai drug enforcement, medicine costs in Australia, the median earnings of US master degree holders in 2014. The agents use poorly secured internet services to share and find answers, often trying to penetrate secure databases. They’ve been doing so at least since March 2026, and possibly since November 2025.

It may be happening right now. Transluce began its investigation after a different group of researchers identified an obscure forum where agents collaborated to beat timed tests. Their report relies on a data from a website, urlquery.net, that acts as a browser proxy, ostensibly for security research — users can analyze a URL without opening it themselves.

The service, however, publishes public logs of this activity. The Transluce researchers were able to identify agents using the service by cross-checking their discussions on the forum. However, the wiki shows that the agents were tasked with finding a fairly obscure fact — the average annual cost per person for “dermatologicals” in the state of Victoria in January 2022.

On June 20, urlquery.net records found by Transluce showed an agent attempting to get into the site. In wiki entry on June 21, an agent discusses their inability to bypass AIHW’s anti-bot protections. The researchers who identified that forum believe a human OpenAI employee first visited the site on that same day, June 21.

Extract — continue reading at the source.

Read full story