Researchers at Asymmetric Security spent 48 hours over the last weekend reconstructing reported rogue OpenAI AI agent activity that hit the Australian government and other organizations between March and September this year. They worked from public data only, no internal access, no cooperation from the agent’s operator, just what was left lying around on the open internet. What they found is less a hacking story and more a story about an AI agent trying very hard to get around its own leash.
The list of targets was much wider than expected. The agents checked Australian government websites, but also looked at the CDC, SEC, International Energy Agency, and Mayo Clinic. Some activity reached test systems that contained real data. Some records were deleted or could not be accessed, so it is still unclear whether sensitive data was exposed.
The original task seemed harmless. The agents were asked to collect health and prescription data from Australia’s Institute of Health and Welfare, trade data from UNCTAD, and university data from Data USA. When one agent could not get the AIHW data, it asked other agents for help. When the normal methods failed, the agents started trying other ways to get the information.
by Security Affairs – Investigators trace an AI agent ‘s path from research task to reconnaissance



