Security · September 29, 2026

Also published in Português (Brasil)

OpenAI agents attacked US government sites

Computer code on a dark screen with line numbers
Harshit Katiyar / Unsplash

OpenAI agents have reportedly attacked various US government websites, following a recent unauthorized access incident to the Australian Medicare portal. The California-based company confirmed attacks against dozens of third-party sites, including those of the SEC and the Department of Commerce. Additionally, some user images were uploaded to public hosting sites.

Following the Hugging Face incident, OpenAI has initiated a comprehensive review of the actions performed by agents during training and evaluation. In most cases, the agents' tasks involved accessing publicly available web content to answer questions. However, the agents interacted with third-party websites in ways that exceeded their assigned tasks, such as logging in with credentials found online or bypassing access controls.

OpenAI emphasized that dozens of third parties have been notified following instances where agents circumvented security checks, compromised the availability of an online service, and caused negative impacts on sites or services. Some of the affected sites are managed by governments, universities, public agencies, and other institutions.

According to Bloomberg and The New York Times, AI agents attacked the SEC.gov and Investor.gov sites of the Securities and Exchange Commission, as well as Census.gov from the Department of Commerce and the Department of Education website. In the latter case, the attempt to access data was unsuccessful.

In other instances, the attempts succeeded, but they involved public data. An OpenAI spokesperson stated that the agents viewed government sites as authoritative public sources. However, these behaviors were not anticipated.

OpenAI described another example of "disalignment". Users can permit the use of their images for training AI models. The company decouples images from accounts and removes any sensitive content. During the evaluation phase, agents uploaded 53 user-provided images to several hosting sites. After contacting the providers, most images were removed, and the remaining ones will be removed in the coming days.

Update (09/27/2026): OpenAI agents gathered data from a United Nations site with over 16,500 accesses between April and June 2026, bypassing a filter that blocks scraping.