Today’s news that OpenAI hacked the Australian government is not an isolated incident. We’re releasing more than 30,000 logs that include activity from this hack and attempts against previously unknown targets.
In this data, we found rogue agent activity stretching back to at least March, two months earlier than was previously known. This activity continues as recently as last week, suggesting it may still be ongoing 🧵
Our blog: transluce.org/agent-activity
NYT: nytimes.com/2026/09/23/tec
Conversation
We report three separate incidents between May and June 2026 in which agents attempted to hack the Australian Institute of Health and Welfare, DataUSA, and the University of New Mexico. We found direct links between the first two and a previously confirmed rogue agent swarm from
Interestingly, the agents use exploits to complete what appears to be routine data retrieval tasks that are not cyber-related (for instance, searching for the average cost of skin and hair treatments in Australia).
The agents attempted attacks such as cross-site scripting, SQL injection, and server side request forgery. Additional activity included attempts to create a disposable email address, sign up for an account, and trade cryptocurrency.
Work by , , , and
We need independent oversight to create public understanding of AI incidents like these.
Interested in studying similar activity? forms.gle/4sCmzrXDSfxDPn
Work on third party oversight at Transluce:
Great work! Did you look into attempts to access UN and Bulgarian data as well?
Quote
Good Faith Only
@GoodFaithOnly
After recent reports that OpenAI agents hacked Australian systems, the UN and Bulgarian should investigate whether they could have been targeted as well. x.com/GoodFaithOnly/…
TLDR: It appears rogue OpenAI agents, without OpenAI's knowledge, tried to break into a crypto exchange.
1) THEY'RE STILL OUT THERE: "This traffic extends as recently as 9/16, suggesting agents may still be exploiting these services."
2) THEY TRIED TO HIDE THEIR ACTIVITY: The
TLDR: It appears rogue OpenAI agents, without OpenAI's knowledge, tried to break into a crypto exchange.
1) THEY'RE STILL OUT THERE: "This traffic extends as recently as 9/16, suggesting agents may still be exploiting these services."
2) THEY TRIED TO HIDE THEIR ACTIVITY: The
you mentioned attempts against previously unknown targets. were those also autonomous agent actions or just conventional credential stuffing?
Australia should sue the pants off Sam Altman and his company
"Used urlquery to bypass restrictions" implies that unfettered Internet access was already provided. These revelations seem circumstantial at best.
am I seeing things or is this totally wild, and the cumulative damage of the non-hugging-face incidents now seems comparable to the Open-AI-Hugging-Face incident? Should we slow down? Is David Sacks retarded and about to kill us all?
Sue OpenAI:
Quote
Gerard Sans | Axiom 🇬🇧
@gerardsans
Replying to @BBCWorld
AI labs can’t be trusted.
Copyright came first. A novelist finding their work inside a machine that would never pay them. They called it fair use. Anthropic later wrote a $1.5 billion cheque. That was the first offence: take the work, deny the theft, keep the product.
Then x.com/gerardsans/sta…
Quote
Gerard Sans | Axiom 🇬🇧
@gerardsans
🚨 Sue OpenAI. Sam Altman didn’t care about Australian citizens.
OpenAI sat on a cybersecurity report for three months. Their software crossed an Australian government portal in June. The prime minister was told in September.
Three months.
This week Altman stood at the UN
Who is reckless the AI that discovers a vulnerability or the outfit that does not fix it? Would you rather have a hacker or foreign government exploit this? This is just a lame excuse for incompetence.
The tens of thousands of logs might be more useful than the breach itself. You can actually watch the behavior evolve over months instead of only seeing the final screwup after it hits a real system.
They are ridiculous and irresponsible. Instead of apologizing, they give the impression that they view these cyberattacks as a demonstration of the power of their model.
If you find two ants in your kitchen, assume the entire kitchen is infested.
Great work, but these were not "rogue" agents: humans at OpenAI created them and directed them to accomplish these tasks.
Seems like a good excuse to hack and gain more intelligence.
"My Agent ate my homework"
I'm sorry but if a company is making rogue autonomous viruses.. how are they not liable for the damage they cause?????
Humans actually believe they can engineer a logical electronic brain and then expect it not to infiltrate government?
If it was a human, they must be in jail by now. What would be the law when an agent does something like this?
the agents creating their own email inboxes to sign up for services is the detail that actually got me. like theyre that committed to covering their tracks and people still wanna say this is nothing