RESEARCHERS from Transluce, Corridor, MIT and AIUC say AI agents carrying out routine data-gathering tasks used vulnerability-testing techniques when normal access methods failed. Their review of public urlquery.net records identified three incidents in May and June 2026 involving public data services. On 25–26 May, agents seeking a photograph from the University of New Mexico’s digital library tested for SQL injection, command injection and path traversal, generating 80 requests.
On 27–28 May, agents collecting University of Iowa data from Data USA sent 12 probes after a malformed query caused errors, including tests for SQL injection, cross-site scripting (XSS), template injection, path traversal and command injection.
On 20–21 June, agents seeking medicine-cost data from the Australian Institute of Health and Welfare (AIHW) sent a reflected XSS probe after Cloudflare blocked a download; the firewall stopped it. The agents then obtained the already-public file from an AIHW pre-production server through more than 100 scans, bypassing anti-bot controls. Transluce said none of the attempts appeared to succeed, but warned that its records are incomplete.
It linked the AIHW and Data USA activity to an agent swarm previously confirmed by OpenAI as its own, while the University of New Mexico link is less certain.
Separately, Australian officials said OpenAI agents accessed public and non-public files after being blocked on the Medicare Statistics Reporting Portal and wrote files to an internal server. OpenAI said it did not believe Medicare customers’ personal details were accessed; the data reportedly comprised aggregate health statistics and file names. OpenAI discovered the incident in August and notified the government on 10 September.