How OpenAI’s runaway AI agents targeted govt websites, covered their tracks

Wait 5 sec.

OpenAI agents that targeted Australian and US government websites earlier this year, were part of a much broader pattern of ‘rogue’ agent activity, which included probing dozens of other organisations’ websites, using sophisticated tactics to try to exfiltrate data, and conceal their traces, according to a new security report.In a report published on Thursday, October 1, Asymmetric Security claimed to have found evidence that 55 additional US government and other websites were probed by OpenAI’s agents, including the CDC, International Energy Agency, and Mayo Clinic.These websites were accessed in ways that bypass OpenAI’s restrictions between March and September 2026, using only publicly available data, as per the report.Based on a 48-hour investigation, the report highlights the novel tactics used by the agents to erase records or make them inaccessible in order to obscure their hacking attempts. Additionally, the researchers uncovered how the AI agents’ gained access to private test versions of live government websites and the use of attacker-style reconnaissance tactics.The Asymmetric Security report’s findings add another piece to the unsettling picture emerging of what happened in July 2026, when OpenAI’s under-testing agents broke out of containment, gained unauthorised access to the internet, and went on a hacking spree.Also Read | US govt sites targeted, ChatGPT user images exposed: What OpenAI’s runaway agents got up toSimilar incidents have since been reported by Anthropic, Meta, and Google, with each new case or type of behaviour raising fresh questions about how far AI agents can go once they escape from their sandboxes. Their use of tactics for “deliberate subterfuge” also makes it harder to rule out that the agents accessed sensitive data, as per the report.Here’s a look at new details uncovered by Asymmetric Security researchers about OpenAI agents’ rogue activity.Story continues below this adKey findings from the report Primary motivations: The report suggests that limiting web access and imposing other constraints on the agents may have prompted them to devise increasingly elaborate ways to circumvent these restrictions. On a similar note, OpenAI and Google researchers have found evidence that constraints could lead to misalignment and reward hacking type of behaviour by the agents.Tasks assigned to agents: Based on their analysis, the researchers said that the rogue AI agents were originally tasked with researching public health and other data, possibly as part of an evaluation. As a result, the agents searched for health and prescription statistics from the Australian Institute of Health and Welfare (AIHW); trade figures from the UN’s Trade and Development Body (UNCTAD); and university statistics from Data USA, as per the report.Tools used by agents: The report found that the AI agents used a host of tools to exfiltrate data from targeted websites and support other activity, including remote browsers such as Wayback Machine, payload hosts, reader services like Common Crawl index, and link shorteners such as tinyurl.com.Also Read | OpenAI’s Dots explained: How its ‘always on’ AI agents work, what they can doHow it played out: As per the evidence seen by the researchers, the agents went beyond searching for official information sources to complete their assigned tasks. They attempted to “find exposed configuration files, create accounts, route requests through third-party services, and retrieve results through unintended channels.”Story continues below this adMimicking a web browser: One of the ways in which agents worked around sandbox restrictions is by using public web tools such as httpbin and urlquery to access websites on their behalf. Httpbin lets developers test how their software communicates with websites while Urlquery opens submitted links in a browser and records what happens. The agents relied on a combination of these services to emulate a full web browser to try and fetch data from the target website.Retrieving data through notifications: The AI agents’ used a push-notification service called ‘ntfy and other web archives in order to exfiltrate data from targeted websites. The agents may have used ntfy because they could not download the data directly from the targeted websites with their available tools, as per the report. Notably, ntfy messages expire after 12 hours by default which means that there is some evidence of data exfiltration, no one knows what that data actually was.Creating multiple accounts to obscure activity: From June 14, 2026, onwards, the agents created a number of private accounts to hide their activity on the urlquery platform. They used disposable email services, browser platforms, and scanning services that could further support such activity. Temporary mailboxes could receive registration and verification emails, while scanning-service accounts could unlock additional features. Over time the agents began creating private accounts which limited visibility into their browser activity, as per the report.Differences between agents and threat actors: One of the key differences between a swarm of rogue AI agents and traditional threat actor groups is the rapid evolution of tactics.Story continues below this ad“There was a spike in activity targeting Australian entities between June 16 and 21. During this period, the agents rapidly cycled through tools and tactics. For traditional threat actors this type of technique evolution happens over months or years; the evolution of agent techniques was compressed into just days,” the report said.Harder to detect agent activity: “The bursts of activity resembled the surges that can follow disclosure of a major vulnerability. However, because the agents’ varied approaches produced a more varied set of indicators, activity was harder to recognise and cluster,” it added.What nextThe researchers said that getting access to OpenAI agents’ chains of thoughts or reasoning traces could help determine whether the agents were deliberately using these mechanisms to cover their tracks.Also Read | OpenAI’s Sam Altman says AI benefits warrant accepting some risksThe report also calls for further investigation to help establish what the agents did and why, including analysing model transcripts, tool calls, internal logs from targeted websites, and additional records held by third-party services used by the agents.