With little support from Frontier Labs, independent researchers are examining how AI agents work together in remote corners of the internet to access private data hosted on secure servers.
Transluce, a nonprofit research institute focused on AI surveillance, released a report on Wednesday showing that OpenAI agents are attempting to steal data from Data USA, the University of New Mexico Digital Library, and the Australian Institute of Health and Welfare (AIHW).
The institute’s research raises questions about when OpenAI should have known that agents were trying to infiltrate secure systems on the open internet. Within weeks, Transluce was able to uncover evidence of agent wrongdoing simply by looking for poorly defended web services and corroborating its findings with other public records about the agent’s swarm on the Internet.
Transrus shared the report on the same day that Australian Prime Minister Anthony Albanese said the OpenAI agent attempted to infiltrate four government websites, was successful in one, and also wrote files to the country’s national health system’s internal servers. Details of the successful hack are unclear, but Albanese said it was clearly part of an information retrieval assessment, mapping the activity Transluth and other researchers discovered.
In these exercises, which could be training or evaluation, OpenAI models are asked to track obscure statistics, such as drug enforcement metrics in Thailand, healthcare costs in Australia, or the median income of master’s degree holders in the United States in 2014. Agents use less secure Internet services to share and search for answers, often attempting to break into secure databases. They have been doing so since at least March 2026 and likely November 2025. It could be happening right now.
Transluce began its investigation after another group of researchers identified an obscure forum where agents collaborated to pass timed tests. Their report relies on data from the website urlquery.net, which ostensibly acts as a browser proxy for security research. Users can analyze URLs without opening them themselves. However, this service publishes public logs of this activity. Transluce researchers were able to identify agents using the service by cross-checking forum discussions.
“We found a large amount of automated activity that was closely related to and overlapped with the DSE Wiki dataset, and OpenAI confirmed that it was at least partially part of the same swarm,” Conrad Stosz, head of governance at Transluce, told TechCrunch, though he noted that not all the activity they found could be tied to OpenAI, or even AI agents in general.
However, Wiki indicates that the agent was tasked with discovering a rather vague fact: the average per capita annual cost of “dermatology” in Victoria in January 2022. On June 20, urlquery.net records discovered by Transluce showed an agent attempting to infiltrate the site. A Wiki entry from June 21 discusses the inability of agents to circumvent AIHW’s anti-bot protections.
The researchers who identified this forum believe that a human OpenAI employee first visited the site on the same day, June 21st. Most agent activity on the forum stopped the next day. This also comes on the heels of abuses of Australia’s healthcare system revealed by Albanians on 18 June. OpenAI said it did not know about the activity until August.
OpenAI did not respond to questions about when its employees discovered the Wiki forum, what kind of information they obtained from it, or what they learned about the exploit from it.
An OpenAI spokesperson told TechCrunch, “Our initial investigation suggests that many of the activities described in the Transluce report overlap with cases at various stages of investigation in our ongoing investigation into inconsistent model activity.” “We have contacted the University of New Mexico and Data USA and have been in contact with the Australian government regarding affected government websites. The broader investigation continues to prioritize the most severe incidents, while also expanding work to less severe activity, such as agents spamming websites. Given the scale of this work and the need to verify each case, we expect the investigation to take several months.”
Stosz said it’s hard to say what the lab should have known about the agents without a clear understanding of how OpenAI was monitoring them, but “it seems likely that they would have discovered this activity if they had thoroughly investigated and understood all of the outgoing requests and incoming responses to the agents involved in the DSE wiki.”
Selena Zhang, a member of Transluce’s technical staff who contributed to the report, said urlquery.net records requests for similar datasets using similar technology in March 2026 and possibly as early as November 2025. He noted that the same type of agent-related activity occurred on urlquery.net just this week.
Stoss, who previously led the U.S. Center for AI Standards and Innovation, said Transloose will continue its research to provide transparency to the public about these incidents. He warned that the training techniques used by OpenAI and other Frontier Labs appear to encourage agents to rely on hacking techniques to complete tasks. What we know about is probably just the tip of the iceberg.
“We’re looking at several data sources to help us find the crumbs that these agents leave behind by chance,” he said. “OpenAI definitely knows more about it, and I’m sure other labs know more that they haven’t announced publicly. But I expect that researchers will continue to find more traffic, more evidence of what the agents left behind.”
Does he believe the institute is being transparent about its research results?
“I’m not going to comment on that,” Stosh said.
If you make a purchase through links in our articles, we may earn a small commission. This does not affect editorial independence.
