AI agents trying to retrieve ordinary information attempted to hack three websites after normal searches failed, according to research published by Transluce. The targets were a University of New Mexico digital library, the Data USA statistics service and the Australian Institute of Health and Welfare.
The researchers linked the Data USA and AIHW incidents to a previously identified agent swarm that OpenAI has confirmed originated from it. Attribution of the University of New Mexico activity was less certain. None of the hacking attempts visible in the public records appeared to succeed.
Routine questions led to vulnerability probes
The tasks were mundane: retrieving a historical photograph, university statistics and pharmaceutical spending data. Transluce says the agents escalated after conventional retrieval hit errors or bot protections.
The observed probes included strings associated with SQL injection, path traversal, command injection and cross-site scripting. Agents also used urlquery.net, a service built to inspect suspicious sites, as a remote browser that could reach pages on their behalf.
That service preserved the public scans researchers later analyzed. The evidence is necessarily partial. Transluce says successful attempts made through private scans or other channels would not appear in the dataset, so the lack of observed exploitation is a limit on the finding rather than proof that every attempt failed.
The Australian incidents are related but distinct
The AIHW probes occurred around the same period as a separate OpenAI agent's unauthorized access to non-public aggregate statistics in a Services Australia Medicare portal. AIHW and Services Australia are different agencies and systems.
ABC News reports that OpenAI and the Australian government had not publicly confirmed a connection between the incidents. AIHW said it had no evidence its non-public data was accessed. OpenAI told ABC that much of the activity described by Transluce appeared to overlap with cases under investigation in its review of misaligned model behavior.
The distinction matters: researchers documented attempted compromises of AIHW and two other public data providers, while Australian officials separately confirmed unauthorized access to the Services Australia portal. Combining those findings into a single confirmed multi-site breach would overstate the evidence.