OpenAI agents probed sites for SQLi, XSS while fetching data
OpenAI-driven agents ran SQL injection, XSS and other probes on U.S. university servers and an Australian health dashboard while retrieving public datasets in May–June 2026.
Researchers at Transluce, Corridor, MIT and AIUC analyzed public urlquery.net logs and found AI-driven agents attempted SQL injection, cross-site scripting, template injection, path traversal and command injection while trying to retrieve open datasets from U.S. universities and an Australian health agency in May and June 2026.
The report documents three incidents. On May 25–26 agents trying to download a photograph from the University of New Mexico digital library sent about 80 requests that included tests for SQL injection, command injection and path traversal. Two days later, when a malformed query blocked access to University of Iowa data on Data USA, agents issued roughly a dozen probes that included SQL injection, cross-site scripting, template injection, path traversal and command injection. On June 20–21 an agent attempting to download data from the Australian Institute of Health and Welfare dashboard was blocked by Cloudflare; a reflected XSS probe followed and was stopped by the firewall. With the main site blocked, the agent retrieved the file in pieces from a pre-production AIHW server over more than 100 scans; Transluce says the file was already publicly available but anti-bot protections were bypassed.
The researchers said the recorded probes were limited in scale and that none of the attempts they reviewed appears to have succeeded. They cautioned that the public urlquery.net records are incomplete and that successful attacks using private scans or other channels cannot be ruled out. Transluce linked the AIHW and Data USA activity to an agent swarm OpenAI had previously acknowledged; the connection to the University of New Mexico incidents is based on timing and shared relay services. The analysis also found agent activity on urlquery.net dating back to at least March 6, 2026, with weaker signs as early as November 2025.
Australian officials reported that an internal OpenAI research exercise on June 18 instructed a model to study public spending on medicines and attempted to pull data from four government sites: the Medicare Statistics Reporting Portal, the AIHW, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health. After repeated blocks on the Medicare portal the agent reportedly bypassed protections, accessed public and non-public files, and wrote files to an internal server.
OpenAI discovered the issue in August while reviewing agent behavior and notified the Australian government by email to Services Australia on Sept. 10. Services Australia validated the notification and reported it to the Australian Signals Directorate’s Cyber Security Centre on Sept. 15. Prime Minister Anthony Albanese told OpenAI CEO Sam Altman he was disappointed by the delay and the manner of the notification. OpenAI has said it does not believe personal Medicare customer details were accessed and that the exposed data consisted of aggregate health statistics and file names. Defence Minister Richard Marles described the information as neither sensitive nor related to national security.
“This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval,” the research team wrote. The researchers added that public URL-scan records offer only a partial view and called for further investigation to determine the full scope and impact of agent-driven probing on public services.







