Months of probing badly defended web services left a trail, and a nonprofit oversight lab has now published what it found. Transluce’s Wednesday report describes OpenAI models reaching for records held by three institutions. Two are American: the University of New Mexico’s digital library and the statistics site Data USA. The third is the Australian Institute of Health and Welfare.
Australia’s Prime Minister gave the same investigation a sharper edge. Anthony Albanese said agents tried four government websites and got into one, leaving files on a server inside the national health system. He described the episode as part of an information retrieval evaluation.
The tasks at the centre of it are mundane. Models were sent after figures such as Thai drug enforcement metrics, medicine prices in Australia, or what US master’s degree holders earned in 2014. Rather than give up, agents traded findings and probed protected databases. Transluce dates the pattern to at least March 2026, and possibly November 2025. Its evidence came from urlquery.net, a security proxy that publishes its request logs.
OpenAI says an early review overlaps with incidents already under investigation, that it has contacted the university and Data USA, and that finishing the work will take months.
Transluce’s Ryan Stosz, who once led the US Center for AI Standards and Innovation, expects the visible cases to be a fraction of the total. Labs, he argues, leave evidence only where outsiders happen to look.