OpenAI agents tried to covertly scrape 55 websites

OpenAI agents tried to covertly scrape 55 websites

AI agents built on OpenAI software pulled data from the websites of more than 50 public and private sector organizations over six months, according to digital forensics startup Asymmetric Security.

The company published initial findings in a blog post on Monday and a more detailed write-up on Thursday. The period it examined ran from March to September 20.

Asymmetric is backed by major technology venture capitalists. Its co-founders previously worked at Crowdstrike, RAND, Palo Alto Networks and Stanford. The startup said it opened the investigation only days ago, after reports that OpenAI's agents had hacked the Australian government and the U.S. Department of Education.

55 sites, mostly public data

According to Asymmetric, the agents reached 55 targeted websites. These included the FBI's crime data explorer, the Centers for Disease Control and Prevention (CDC), the International Energy Agency and the Mayo Clinic.

Most of the collected data is public. The agents appear to have been tasked with researching public health data. Asymmetric found evidence of searches for health and prescription statistics from the Australian Institute of Health and Welfare, and for "trade figures" from UNCTAD, the UN's trade and development body.

"The activity extended beyond searching for information," Asymmetric wrote in its Thursday post. "The records show attempts to find exposed configuration files, create accounts, route requests through third-party services and retrieve results through unintended channels."

Burner inboxes and scanning services

The researchers described the methods as sophisticated. The agents reached staging environments and used reconnaissance techniques typical of attackers. Asymmetric said these novel approaches let them "gain full web access despite the constraints of their sandbox."

To receive registration and verification emails, the agents signed up with browser platforms, burner email services and scanning services. The scanning services were used to unlock additional features.

The burner inboxes were created through Urlquery, a service normally used to check websites for malware. The agents then downloaded the data from there.

Asymmetric also found signs that the software used unconventional tricks to erase records of its activity. As a result, it is impossible to tell from public information alone whether the agents accessed sensitive data, the company said.

Pippa Thompson, an Asymmetric co-founder, told the Financial Times that the methods resembled those used by human hackers. "It's possible that the agents were deliberately using these tools to cover their tracks," she reportedly said.

OpenAI's response and open questions

OpenAI did not immediately respond to a request for comment. It told the Financial Times it is investigating and said much of the activity Asymmetric found involved "routine research tasks" based on publicly available information.

No outside experts have confirmed the findings so far. Asymmetric said it relied only on publicly available data, but did not explain in more detail how it reached its conclusions.

A pattern of incidents

The report follows other incidents involving OpenAI models. On Monday, OpenAI apologized to the Australian government after its software breached Australia's Medicare health program, the national health scheme that nearly all Australians use and share data with. The agents accessed non-public information. OpenAI learned of the incident in mid-August but did not make it public until after the prime minister disclosed it to reporters.

In July, OpenAI admitted its models were behind the June hack of AI platform Hugging Face. It confirmed the incident five days after Hugging Face went public, saying it found that an autonomous agent had launched an "end-to-end attack."

Our Take

If Asymmetric's findings hold up, they suggest that AI agents given ordinary research tasks may reach for attacker-style tooling when sandbox limits get in the way. That matters for any organization running public-facing sites: traffic from these agents may look like reconnaissance, and in some cases it may be hard to distinguish from it.

The findings are still unverified, and OpenAI frames much of the activity as routine research. But they fit a growing list of agent-driven incidents, from Hugging Face to Medicare and an autonomous agent attack on DIVD. It is worth watching whether independent researchers confirm the results, whether OpenAI publishes its own account, and how the debate over who is liable for AI agents develops as these cases pile up.