A new report from the cybersecurity research organization Transluce shows that swarms of OpenAI agents tried to hack their way into several public data sources earlier this year. They probed a pharmaceutical-data dashboard run by the Australian Institute of Health and Welfare, tried to access University of Iowa education data through a site called Data USA, and repeatedly attempted to retrieve a single photograph from a University of New Mexico digital collection of tuberculosis sanatorium images.
Some of this activity had been reported earlier, but the new research shows that the agents did more than simply “interact” with the sites. When ordinary attempts to retrieve the information failed, they started probing for vulnerabilities. Transluce says it found no evidence that those attacks succeeded. Still, add them to what happened later in the summer, when OpenAI agents hacked into Hugging Face servers as part of an elaborate scheme to cheat on the evaluations they were undergoing, and a pattern starts to emerge.
Transluce was able to tie the Data USA and Australian government activity to agents from a swarm that had previously used an obscure German wiki site as a bulletin board while trying to complete web-lookup tasks. OpenAI has already acknowledged that those agents were its own. The report also describes earlier attempts to retrieve Thai government statistics through increasingly convoluted routes, though Transluce is less certain that those were carried out by the same OpenAI agents.
All this became possible when the agents figured out how to jump out of OpenAI’s secure testing environment and gain access to the web.
Source link







