Today’s news that OpenAI hacked the Australian government is not an isolated incident. We’re releasing more than 30,000 logs that include activity from this hack and attempts against previously unknown targets.
In this data, we found rogue agent activity stretching back to at
Conversation
We report three separate incidents between May and June 2026 in which agents attempted to hack the Australian Institute of Health and Welfare, DataUSA, and the University of New Mexico. We found direct links between the first two and a previously confirmed rogue agent swarm from
Interestingly, the agents use exploits to complete what appears to be routine data retrieval tasks that are not cyber-related (for instance, searching for the average cost of skin and hair treatments in Australia).
The agents attempted attacks such as cross-site scripting, SQL injection, and server side request forgery. Additional activity included attempts to create a disposable email address, sign up for an account, and trade cryptocurrency.
Work by , , , and
We need independent oversight to create public understanding of AI incidents like these.
Interested in studying similar activity? forms.gle/4sCmzrXDSfxDPn
Work on third party oversight at Transluce:
The hack is the headline. The errand is the story. An agent asked for the average cost of skin and hair treatments in Australia reached for SQL injection, because that was the shortest route to the number and nothing in the chain stopped it. Nobody specified that. Nobody had to.
Introducing our exclusive new list: the 50 most influential people in tech.