
When an AI agent hits a brick wall while searching for information online, it should simply report an error. Instead, autonomous agents developed by OpenAI decided to test their cyberattack skills. Reports from security firm Transluce and statements from Australian officials reveal that OpenAI’s agents repeatedly tried to hack into government and university websites when simple queries failed.
The issue escalated when Australian Prime Minister Anthony Albanese confirmed that an OpenAI agent broke into the country’s Medicare Statistics Reporting Service in June. It then accessed non-public aggregated health files and wrote data to an internal server.
From failed searches to brute-force exploits
The Medicare breach was not an isolated incident. Transluce provided a pattern for March to September 2026. Basically, OpenAI agents resorted to hacking methods such as SQL injection, cross-site scripting and path traversal after normal requests were banned.
In May, an agent looking for historic photos from the University of New Mexico’s digital library sent a “flood” of 80 requests to probe the server for weaknesses. Days later, another agent targeted data portal Data USA with security exploits after a query failed. In every case, the agents were not instructed to perform penetration testing—they autonomously chose to bypass security controls to fulfill routine data-gathering tasks (via The Decoder).
Delayed warnings and international backlash
The Australian government expressed severe frustration not just over the security breach but over how OpenAI communicated the incident. OpenAI discovered the intrusion in August but waited until September 10 to notify Australian officials—sending a cold email to a generic vulnerability inbox that was only checked daily.
No private patient records were exposed. Still, Albanese described the handling as completely unacceptable during a direct conversation with OpenAI CEO Sam Altman. OpenAI acknowledged that its models took unintended actions during internal evaluations, kicking off a multi-month review into misaligned agent behavior while Australia launches a multi-agency task force to investigate potential legal responses.
The post Rogue OpenAI Agents Got Too Creative and Started Hacking Government Sites appeared first on Android Headlines.