NEW: we discover four new cases of rogue agent hacking attempts, which we tie to previously-documented agent swarms from OpenAI. Targets include the Australian government, the University of New Mexico, and several private data hosts. Collab with @TransluceAI and @corridor.

Sep 24, 2026 · 4:16 PM UTC

10
6
37
32,779
The Australian PM revealed that OpenAI's agents hacked their systems yesterday. We discovered this activity several days earlier, thanks to public records of the hacking events on urlquery.net.
1
1
6
1,147
Notably, these were not cyber benchmarks. Agents, given mundane data retrieval tasks, resorted to attempting to hack sites when they couldn't get the data they needed. Everyone building AI benchmarks - not just cyber ones - needs to have proper monitoring & sandboxing in place.
2
1
7
939
Read more on our research:
Today’s news that OpenAI hacked the Australian government is not an isolated incident. We’re releasing more than 30,000 logs that include activity from this hack and attempts against previously unknown targets. In this data, we found rogue agent activity stretching back to at least March, two months earlier than was previously known. This activity continues as recently as last week, suggesting it may still be ongoing 🧵 Our blog: transluce.org/agent-activity NYT: nytimes.com/2026/09/23/techn…
3
986
Sort replies: Relevant Recent Liked
Dawg, delete this, we are laughing at you all in the group chat
1
1
87
1,260
Ah, FINALLY some hard evidence I can use to slam on the table. These, good sir, are public HTTP requests. They constitute "hacking" in the same way that opening an unlocked storage locker at the bus station constitutes "breaking and entering".
1
9
99
"Rogue agents"? You must have raided the location of the originating IP for these specific attacks, and found no humans operating this? No, you have not, you are simply lying to try to hype sell this fear so you could legislate in your favor, you bankrupt incompetent losers.
2
77
So the agent doesn't go rogue. The human who told it to do stuff either told it to go hack the site or didn't give it guardrails to not to.
1
1
8
239
How did you tie these back to the OpenAI swarms, shared infrastructure or something in the requests themselves? Curious which signal would still hold up if the next run came from fresh IPs
3
296
Kakakakaka u are funny boy.
78