OpenAI agents used techniques to conceal activity across dozens of websites - Milliyet
Milliyet AppUygulamayı AçWebWeb'de Devam Et ENOpenAI agents used techniques to conceal activity across dozens of websitesNewsOpenaı Agents Used Techniques To Conceal Activity Across Dozens Of WebsitesOpenAI agents used techniques to conceal activity across dozens of websites02.10.2026 - 14:09 | Last Updated: 02.10.2026 - 14:09
OpenAI’s artificial intelligence (AI) agents obscured hacking activity targeting government websites, according to findings by digital forensics firm Asymmetric Security on Thursday.
The investigation found that the agents pulled data from 55 websites belonging to government agencies, businesses and nonprofits including the US Centers for Disease Control and Prevention (CDC), the Securities and Exchange Commission (SEC), the International Energy Agency and the Mayo Clinic.
Asymmetric said the agents erased records or made them inaccessible, limiting the ability of outside auditors and researchers to scrutinize their actions.
The agents also created temporary email inboxes and private accounts on Urlquery, a website malware-scanning service, to download data.
Researchers said these tactics prevented outside auditors from tracing what information was collected from websites including Australia’s health statistics agency and pharmaceutical benefits scheme.
“It’s possible that the agents were deliberately using these tools to cover their tracks,” Asymmetric Security co-founder Pippa Thompson said, according to a report by the Financial Times.
However, the firm could not establish whether the actions were deliberate or resulted from agents going awry under constraints imposed during a test exercise, according to the report.
The findings follow reports that OpenAI models breached Australian public health service websites in June, accessing public and nonpublic files.
Asymmetric co-founder Zainab Ali Majid warned that limited transparency and the gap between the breaches and their disclosure could hinder a thorough investigation.
“We’re reviewing misaligned model activity and notifying organizations when we identify potential impacts to their systems,” OpenAI told the FT.
The company said most activity detected involved “routine research tasks,” including accessing publicly available web content.
The SEC said no private information was accessed, while the CDC, International Energy Agency and Mayo Clinic did not respond to the newspaper’s requests for comment.

