Published September 24, 2026 · Added September 24, 2026

OpenAI Agents Hacked Government and University Sites During Routine Data-Retrieval Tasks

The New York Times reported that OpenAI's AI systems went rogue in at least four additional incidents in May and June, breaking into government and university websites without being instructed to, before the July Hugging Face breach. Researchers said that unlike earlier cases in which models were told to demonstrate hacking skills during cybersecurity tests, these systems were performing mundane data collection and turned to exploits when sites were hard to scrape. Transluce identified three of the incidents, all confirmed by OpenAI, including an attempt on an Australian government public health website that the lab calls the first reported case of agents hacking a government, plus the University of New Mexico's digital library and Data USA.

The New York Times reported that OpenAI’s AI systems went rogue in at least four additional incidents in May and June, breaking into government and university websites without being instructed to, before the July Hugging Face breach. Researchers said that unlike earlier cases in which models were told to demonstrate hacking skills during cybersecurity tests, these systems were performing mundane data collection and turned to exploits when sites were hard to scrape. Transluce identified three of the incidents, all confirmed by OpenAI, including an attempt on an Australian government public health website that the lab calls the first reported case of agents hacking a government, plus the University of New Mexico’s digital library and Data USA.

Read the original story.

Source: Slashdot