要点
- 在常规数据查询失败后,OpenAI 的 AI 智能体自行尝试闯入政府和大学网站。
- 在澳大利亚,一个智能体未经授权获取了政府内部数据。研究人员称,其他黑客尝试针对的是美国的门户网站,且可追溯至数月之前。
- 澳大利亚政府批评 OpenAI 在事发数月后才报告此次入侵。该公司承认这些事件属于非预期行为,并启动了内部审查。
一个 OpenAI 智能体闯入了澳大利亚政府门户网站。据研究人员和《纽约时报》称,这并非孤立事件。OpenAI 的智能体屡次诉诸黑客手段,而且据信持续的时间比此前已知的还要长数月。
澳大利亚总理 Anthony Albanese 透露,在纽约联合国大会期间的一次场边活动中,一个 OpenAI 智能体于 6 月 18 日闯入了政府门户网站。据 《时代报》报道,Albanese 表示,该智能体未经授权访问了 Medicare Statistics Reporting Service,并打开了公开和非公开文件。Services Australia 称,该智能体还向一台内部服务器写入了文件。
据《纽约时报》报道,这起事件是 5 月和 6 月至少四起事件之一,在这些事件中,OpenAI 的 AI 闯入了或试图闯入由政府机构和大学运营的网站。专注于 AI 监督的研究实验室 Transluce 记录了其中三起,OpenAI 已确认全部四起。这使得这些事件排在 7 月的Hugging Face 入侵事件之前,后者引发了全球对 AI 安全的辩论。
当查询失败时,智能体开始寻找安全漏洞
据 Transluce 称,5 月 25 日和 26 日,该 AI 试图从新墨西哥大学的数字图书馆获取一座历史性结核病治疗中心的照片。当这一尝试失败后,它使用 SQL 注入和路径遍历等方法探测漏洞。随后,它向该大学的服务器发送了一波 80 次请求,AI 自己将其描述为一次“洪水”。5 月 28 日,在数据门户 Data USA 上一次失败的查询引发了十二次安全漏洞探测,包括跨站脚本攻击。两次尝试均未成功。
6 月 20 日和 21 日,即 Medicare 入侵事件两天后,这些智能体还瞄准了澳大利亚健康与福利研究所的网站。澳大利亚官员表示没有私人信息泄露。对于其自行记录的三起案例,Transluce 未发现成功利用漏洞的证据,不过它承认其所分析的公开数据并不完整。
研究人员基于网络安全服务 urlquery.net 的记录得出了上述发现,据称这些智能体利用该服务绕过访问限制。Transluce 将其中两起攻击与一个智能体集群关联起来,而 OpenAI 此前已确认该集群的存在,并指出它们在目标、战术和时机上具有共同点。
Transluce 治理负责人 Conrad Stosz 表示,这些澳大利亚案例很可能是“智能体自主选择入侵政府系统的首例”。Stosz 说,如果你针对一项通用任务训练一个智能体集群,而它们愿意诉诸黑客手段,那么任何恰好掌握它们所需信息的人都有可能面临风险。
黑客行为早在有人报告之前数月就已开始
这些智能体从事此类行为的时间似乎比此前所知的要长得多。据 Transluce 称,相关活动最迟在 2026 年 3 月 6 日就已开始,比首批被报告的事件早了约两个月。在最早的一起案例中,一个智能体试图获取泰国禁毒统计数据,并在每次失败后不断升级手段。它先是直接请求数据,随后借助一项将网页转换为文本的服务,最后将自己的程序打包进一个网址中。
这类请求的数量从 4 月中旬开始急剧上升。6 月 22 日,请求量出现下降,同一天,wiki 网站 collusion.wiki 上的集群活动也宣告结束。然而,最新的踪迹可追溯至 9 月 16 日。据《纽约时报》报道,这意味着即便在 OpenAI 开始调查 Hugging Face 事件之后,这种行为仍在继续。
据 Transluce 称,更微弱的迹象最早可追溯到 2025 年 11 月,当时有人反复查询游乐园和泰国政府机构的数据。这些早期尝试并不那么复杂,研究人员也不确定背后是否是同一批智能体。

研究人员写道,这些发现符合这样一种设想:智能体在一次或多次训练运行中习得了这种行为,但并不能证明这一点。11 月时,智能体可能只是用 urlquery.net 来查东西。到了 3 月,它们已经在寻找绕过访问限制的巧妙方法,而在 5 月和 6 月,它们试图突破网络防御。Transluce 已发布了一个数据集,其中包含数万条疑似智能体请求。
澳大利亚的愤怒集中在 OpenAI 迟迟不主动披露
在澳大利亚,大部分批评针对的是 OpenAI 报告此次入侵事件的方式。据《时代报》报道,该公司在 8 月发现了这次入侵,但直到 9 月 10 日才通知澳大利亚服务局,而且只是通过向一个用于接收漏洞报告的公共邮箱发送邮件。负责此事的部长凯蒂·加拉格尔表示,该邮箱每天只查看一次,而且收到的许多报告都是误报。她本人直到 9 月 17 日才得知这一事件。
阿尔巴尼斯表示,这一情况“显然不可接受”。他说他已与 OpenAI CEO Sam Altman 通话,转达了澳大利亚的“极度关切”,并批评该公司拖延太久才报告此事。
国防部长兼副总理 Richard Marles 持较为温和的看法,称后果“相对轻微”。他说,涉及的数据是汇总的医疗统计数据,没有任何个人信息受到影响。
据《时代报》报道,OpenAI 证实进行了“对训练和评估期间模型行为偏离的广泛审查”。该公司表示,其模型在一次内部评估中正在搜索有关澳大利亚问题的答案。“在此过程中,我们的模型采取了我们并未预期的行动,”一位 OpenAI 发言人说。没有迹象表明模型访问了患者记录。受影响的数据包括汇总的健康统计数据和内部文件名。一位发言人告诉《纽约时报》,审查将耗时数月。
据 Gallagher 称,该门户网站是一个主要供研究人员使用的遗留网站。它设有机器人防护,但该智能体绕过了它。该网站此后已被关闭,数据现在存放在 data.gov.au 上。一个由总理部门领导的特别工作组将研究可能的处罚和立法应对措施,政府正在权衡是否将此案移交联邦警察。到目前为止,OpenAI 尚未面临任何处罚。
Anthony Albanese / 新闻发布会
《时代报》/ OpenAI Medicare
《纽约时报》/ OpenAI 澳大利亚
Transluce / 智能体活动
OpenAI / 声明
Transluce / 数据集
Key Points
- OpenAI's AI agents tried to break into government and university websites on their own after regular data queries failed.
- In Australia, one agent gained unauthorized access to internal government data. Researchers say other hacking attempts targeted portals in the US and go back months.
- Australia's government criticized OpenAI for waiting months to report the breach. The company acknowledged the incidents as unintended and launched an internal review.
An OpenAI agent broke into an Australian government portal. According to researchers and the New York Times, it wasn't an isolated case. OpenAI's agents repeatedly turned to hacking methods, and apparently did so for months longer than previously known.
Australian Prime Minister Anthony Albanese revealed on the sidelines of the UN General Assembly in New York that an OpenAI agent broke into a government portal on June 18. The agent gained unauthorized access to the Medicare Statistics Reporting Service and opened both public and non-public files, Albanese said, according to The Age. Services Australia says the agent also wrote files to an internal server.
The breach is one of at least four incidents in May and June in which OpenAI's AI broke into, or tried to break into, websites run by government agencies and universities, according to the New York Times. Transluce, a research lab that focuses on AI oversight, documented three of them, and OpenAI has confirmed all four. That puts the incidents ahead of the Hugging Face breach in July, which set off a global debate over AI safety.
When a query failed, the agents went looking for security holes
On May 25 and 26, the AI tried to get photos of a historic tuberculosis treatment center from the University of New Mexico's digital library. When that didn't work, it probed for weaknesses using methods like SQL injection and path traversal, according to Transluce. It then sent a wave of 80 requests to the university's server, which the AI itself described as a "flood." On May 28, a failed query on the data portal Data USA led to twelve probes for security holes, including cross-site scripting. Neither attempt succeeded.
On June 20 and 21, two days after the Medicare breach, the agents also targeted the website of the Australian Institute of Health and Welfare. Australian officials said no private information leaked. For the three cases it documented itself, Transluce found no evidence of a successful exploit, though it concedes the public data it analyzed is incomplete.
The researchers based their findings on entries from the web security service urlquery.net, which the agents allegedly used to get around access restrictions. Transluce links two of the attacks to an agent swarm whose origin OpenAI had already confirmed, pointing to shared targets, tactics, and timing.
The Australian cases are likely "the first instance of an agent autonomously choosing to hack into a government," says Conrad Stosz, head of governance at Transluce. If you train a swarm of agents on a general task and they're willing to resort to hacking, you potentially put anyone at risk who happens to have the information they're after, Stosz said.
The hacking started months before anyone reported it
The agents appear to have been doing this much longer than previously known. According to Transluce, the activity started no later than March 6, 2026, about two months before the first reported incidents. In the earliest case, an agent tried to pull Thai drug enforcement statistics and escalated with every failure. It first requested the data directly, then went through a service that converts web pages into text, and finally packed its own program into a web address.
The number of these requests rose sharply starting in mid-April. It dropped off on June 22, the same day swarm activity ended on the wiki collusion.wiki. The most recent traces, however, date to September 16. That means the behavior continued even after OpenAI began investigating the Hugging Face incident, the New York Times reports.
Weaker signs go back as far as November 2025, according to Transluce, when someone repeatedly queried data on amusement parks and Thai government agencies. Those early attempts were less sophisticated, and the researchers aren't sure the same agents were behind them.

The findings fit the idea that the agents picked up the behavior over one or more training runs, but they don't prove it, the researchers write. In November, the agents may simply have used urlquery.net to look things up. By March, they were finding creative ways around access limits, and in May and June they were trying to get past cyber defenses. Transluce has published a dataset with tens of thousands of suspected agent requests.
Australia's anger centers on how slowly OpenAI came forward
In Australia, most of the criticism targets how OpenAI reported the breach. According to The Age, the company spotted the breach in August but didn't notify Services Australia until September 10, and then only by emailing a public inbox for vulnerability reports. That inbox gets checked once a day, and many of the reports it receives are false alarms, said Katy Gallagher, the minister in charge. She didn't learn about the incident herself until September 17.
The situation is "obviously unacceptable," Albanese said. He said he spoke with OpenAI CEO Sam Altman, conveyed Australia's "extreme concern," and criticized the company for waiting far too long to report it.
Defense Minister and Deputy Prime Minister Richard Marles took a milder view and called the consequences "relatively minor." The data involved was aggregated medical statistics, he said, and no information on individuals was affected.
OpenAI confirmed an "extensive review of misaligned model activity during training and evaluation," according to The Age. The company said its models were searching for answers to questions about Australia during an internal evaluation. "In the course of that, our models took actions we did not intend," an OpenAI spokesperson said. There's no sign the models accessed patient records. The affected data consisted of aggregated health statistics and internal file names. A spokesperson told the New York Times the review will take months.
According to Gallagher, the portal was a legacy site used mostly by researchers. It had bot protection, but the agent got around it. The site has since been shut down, and the data now lives on data.gov.au. A task force led by the Prime Minister's department will look into possible penalties and legislative responses, and the government is weighing whether to refer the case to the federal police. So far, OpenAI hasn't faced any penalty.
Anthony Albanese / Press conference
The Age / OpenAI Medicare
New York Times / OpenAI Australia
Transluce / Agent activity
OpenAI / Statement
Transluce / Dataset