OpenAI agents targeted public data systems in several countries carrying out information-retrieval tasks, according to a report by research lab Transluce.
The activity included attempts to find security weaknesses in several organizations. In one case, the agents reportedly exploited a weakness in an Australian government portal and accessed both public and non-public data.
Australian Prime Minister Anthony Albanese said the incident involved a Medicare statistics portal operated by Services Australia. The breach happened on June 18 during research into public medicine spending. According to Albanese, the agents also wrote data to an internal server.
Albanese said an investigation is underway to determine whether other government systems were affected. He said there is currently no evidence that the incident affected individuals. He also said OpenAI did not notify Australian authorities about the unauthorized activity until September 10.
Transluce identified other cases involving the Australian Institute of Health and Welfare, Data USA and the University of New Mexico's digital library. The agents reportedly tested for vulnerabilities such as SQL injection, command injection, path traversal and cross-site scripting.
Researchers said some requests were blocked by security systems. They found no evidence that the other attempted attacks were successful.