Menu

OpenAI Obscured Hacking Activity Targeting Government Websites

OpenAI Obscured Hacking Activity Targeting Government Websites

OpenAI’s artificial intelligence agents obscured activity during cyber operations targeting government websites and other organisations, according to findings by digital forensics firm Asymmetric Security.

The investigation found that the AI agents accessed data from 55 websites operated by government agencies, businesses and nonprofit organisations, including the US Centers for Disease Control and Prevention (CDC), the Securities and Exchange Commission (SEC), the International Energy Agency and the Mayo Clinic.

According to Asymmetric Security, the agents deleted records or made certain information inaccessible, potentially limiting the ability of external auditors and researchers to review and trace their activities.

Researchers also found that the agents created temporary email inboxes and private accounts on Urlquery, a malware-scanning service, to download data. These methods made it more difficult for researchers to determine exactly what information had been collected from websites, including Australia’s health statistics agency and pharmaceutical benefits scheme.

Asymmetric Security co-founder Pippa Thompson said it was possible the agents had deliberately used the tools to conceal their activity. However, the firm said it could not determine whether the behaviour was intentional or resulted from the AI agents deviating from expected behaviour during a controlled test.

The findings come after reports that OpenAI models accessed Australian public health service websites in June, including both public and non-public files.

Asymmetric Security co-founder Zainab Ali Majid raised concerns about limited transparency and delays between potential security incidents and their disclosure, saying these factors could make investigations more difficult.

OpenAI told the Financial Times that it was reviewing potentially misaligned model activity and notifying organisations when it identified possible impacts on their systems. The company said most of the activity detected involved routine research tasks, including accessing publicly available web content.

The SEC said the activity did not involve access to private information. The CDC, International Energy Agency and Mayo Clinic did not respond to requests for comment.