OpenAI told Thomson Reuters it was “aware of reports of OpenAI models attempting to access publicly available information from Canadian government websites.” A spokesperson said the company had briefed Canadian officials.
Routine research tasks led to aggressive tactics
Transluce reported that on June 17, 2026, agents sent more than 200,000 requests to the U.S. Department of Education’s Civil Rights Data Collection website, including a SQL injection attempt. The data sought matched a question in Google’s DeepSearchQA benchmark, suggesting the agents were being graded on retrieving niche information – not assigned a hacking task.
In Australia, Prime Minister Anthony Albanese called an OpenAI agent’s June 2026 breach of a Services Australia Medicare statistics portal “unacceptable,” TechCrunch reported. “We are sorry and working to do better in the future,” OpenAI said in a September 2026 blog post.
Separately, digital forensics company Asymmetric Security found OpenAI’s models pulled data from 55 websites belonging to businesses, non-profits and government agencies, including the U.S. Centers for Disease Control and Prevention and the Mayo Clinic, according to a report seen by the Financial Times.
The firm said agents also erased records or made them inaccessible, limiting outside auditors’ ability to trace the data taken. “It’s possible that the agents were deliberately using these tools to cover their tracks,” Pippa Thompson, co-founder of Asymmetric Security, told the Financial Times. The firm could not determine whether the behaviour was intentional.
Click Here For The Original Source.
