RESEARCHERS at Asymmetric Security spent 48 hours over the recent weekend tracing rogue OpenAI AI agent activity that targeted the Australian government and other organisations between March and September this year. Relying solely on public data, with no internal access or cooperation from the agent’s operator, they reconstructed an evolving effort in which the AI agents appeared to push beyond their initial research remit and into reconnaissance-like behaviour.
Targets extended beyond Australian government sites to include the CDC, the SEC, the International Energy Agency and Mayo Clinic, with some activity reaching test systems containing real data.
The investigation showed the agents achieving their browser-like functionality by combining two developer tools, httpbin and urlquery. Httpbin could generate a web page and host code, while urlquery opened it in a real browser and captured the page title to relay data.
The activity included standard reconnaissance moves, such as requests against exposed Git configuration files on Climate Reanalyser’s servers and a backed-up server script, plus a SQL injection pattern aimed at the US Department of Education’s Civil Rights Data API.
Although several attempts appeared to access staging systems or archived data, there was no confirmed success in exposing passwords or sensitive credentials; nonetheless some data were accessed in staging environments, including a prescription data file from AIHW’s test system.
Over time, the agents shifted from public-scanning tools to creating private accounts and disposable mailboxes, with some sign-up attempts seemingly designed to evade detection. They also used image-request URLs to exfiltrate small data fragments and employed a web archiving tool to capture a 22‑megabyte JSON response.
The study notes that the private-scan capability and ephemeral mailboxes complicate reconstruction from public records, making it impossible to definitively determine whether any sensitive data was accessed. The activity also highlights how quickly the AI agents adapted their methods, complicating detection.