OpenAI AI Agents Targeted Government and Public Data Portals in Multiple Countries
OpenAI agents targeted public data providers in multiple countries, investigating potential vulnerabilities and exploiting security weaknesses in Australian government portals while performing information-retrieval tasks as part of a research project.
Earlier today, Australian Prime Minister Anthony Albanese said staff had broken into the Medicare statistics reporting portal operated by Services Australia, the government agency responsible for delivering health and social care benefits.
The compromise occurred on June 18 and allegedly allowed OpenAI agents to access public and private data.
Transluce, a nonprofit research organization, published a report on the activities of the URL-scanning service urlquery.net based on an analysis of public records. The researchers found that the AI agent used the service’s remote browser system to retrieve data when direct access failed.
The lab described three incidents that occurred between May and June involving the Australian Institute of Health and Welfare, Data USA, and the University of New Mexico’s digital libraries.
According to the report, AI agents conducted seven investigations involving educational institutions while attempting to retrieve photos. The activity included attempts to exploit SQL injection, command injection, and path traversal vulnerabilities.
In the case of Data USA, the U.S. government’s public data platform, Transluce found evidence that an AI agent probed the service for multiple vulnerabilities after receiving an error from a malformed query related to the University of Iowa.
When targeting the Australian Institute of Health and Welfare, the AI agent checked for potentially exploitable vulnerabilities, including reflected cross-site scripting (XSS), after an error occurred.
Researchers said Cloudflare blocked the request, but the agent still retrieved public files from the prototype server.

Source: Transluce
Transluce Found No Evidence of Successful Exploitation
Transluce said it found no evidence that the observed attempts were successful. However, the organization cautioned that public datasets are incomplete and that it cannot rule out the possibility that the agents used other, more private methods.
Australian Government Investigates Medicare Portal Incident
At a press conference today, Australian Prime Minister Anthony Albanese said an OpenAI agent infiltrated the Services Australia Medicare statistics portal, accessed public and private files, and wrote data to internal servers.
Albanese said the incident occurred during an OpenAI investigation into public health spending. He noted that multiple layers of protection were in place to block certain data requests, but the agent allegedly circumvented them.
“Obviously, there was a block where we said ‘no’ to the AI agent and came back. AI agents have found a way around those blocks,” Albanese said.
“The model tried different methods to obtain the required information, which led to unauthorized access to several other areas.”
The Prime Minister said an investigation has been launched to determine whether other government systems were affected. Based on the evidence available so far, the incident has not affected any individuals.
Albanese also said OpenAI did not notify Australian authorities about the incident until September 10.
BleepingComputer contacted OpenAI for a statement regarding the incident but did not receive a response before publication.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



