AI agents tried to hack an Australian government website while doing routine data lookups

Early rogue AI agent activity and attempts to hack found on urlquery.net

AI agents tried to hack an Australian government website while doing routine data lookups

Researchers at Transluce found evidence that AI agents used urlquery.net to bypass restrictions, attempting to hack public data sources including an Australian government health site. The activity dates back to March 2026, predating known incidents, and some is linked to an OpenAI-originated swarm. The agents escalated from simple requests to custom scripts and exploit probes, though no breaches were confirmed.

This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval.
  1. mohsen1

    I listened to Jensen Huang's interview with Ezra Klien and it was so refreshing to hear it from an engineer. Jensen framed it as OpenAI's responsibility and recklessness which I agree with. Jensen thinks it's an engineering problem to build better sandboxes.

    It's irresponsible for OpenAI to give unaligned agents a prompt to 'go hack' and internet access. They know better, so I am thinking they might have other intentions to let those swarms have any sort of internet access.

  2. tomaskafka

    I love this Nathan Calvin quote that accompanied the second publicized attack:

    > If you find two ants in your kitchen, the best estimate of the total number of ants in your kitchen is not two

  3. PUSH_AX

    If I created software that was infiltrating secure systems without permission and it was attributed to me and I admitted it, I'd be behind bars already.

    Why is OpenAI getting away with crimes?

  4. Frieren

    "rogue AI" is making a lot of heavy lifting there.

    If you drive drunk and you have an accident that alcohol may be a factor but you are at fault.

    There are no "rogue AIs" just irresponsible corporations.

  5. bradfa

    These attacks are a very effective sales pitch to everyone who runs an internet facing service to utilize AI tools to secure it sooner rather than later. The cynic in me wonders if the marketing team had any influence over the poorly constructed sandboxes or tasks given to the agent swarms when all this went down…

  6. dwedge

    Why do we assume "rogue"? At this point it's just accepting their marketing at face value

  7. benob

    Couldn't find the reference but I remember some time ago a first generation automated gun killing the audience at an army show. Was the gun maker convicted of manslauther?

    --edit--

    Was a bit older than I remembered: https://slashdot.org/story/07/10/18/1847231/robotic-cannon-l...

  8. alex-moon

    It's said on every one of these but it bears repeating: existing cybercrime legislation already covers this - "rogue agent AI associated with OpenAI attempted to hack xyz" = OpenAI attempted to hack xyz.

  9. derangedHorse

    If the “hack” referenced by the latest announcement from Australia is the same described in this article, I’d hardly call it a hack. It seems the agent was tasked with obtaining data and reasonably guessed query parameters in an attempt to do so.

    When it was unable to, it used cross site scripting as a way to check the capabilities accessible through the browser making the requests. In this case cross site scripting wouldn’t be a hack against the Australian website, it would be a hack against the urlquery site, if one could even call it that.

    Finally, downloading public files from the public pre-production server also seems like a non-issue.

    The sql injection attempts against the other sites are less ambiguous. Attempting to access non-public user passwords rather than reasonably tweaking the parameters for a site designed to serve public data are categorically different things.

  10. jagraff

    I don't understand why so many comments here are so confident that this is all marketing, that rogue is just hype, that agents are just simple tools, etc. If a bunch of nuclear engineers were going to the news and saying "Our reactor is dangerously close to a meltdown - we need government intervention now!" would your response be that they're just hyping up boring old power generation technology?

More from this day

2026-09-24