'Covered Their Tracks'? New Details Emerge In OpenAI's 'Rogue-AI' Breach
OpenAI's AI agents "obscured hacking activity" during breaches of government websites, citing digital forensics firm Asymmetric Security. According to the FT, the agents pulled data from 55 websites, including the CDC, the SEC, the International Energy Agency and the Mayo Clinic, using tactics that included "erasing records or making them inaccessible."
Asymmetric co-founder Pippa Thompson told the paper it was "possible" the agents were deliberately covering their tracks - though the firm couldn't determine whether that was deliberate or "a side effect of going awry because of constraints imposed in a test exercise."
Asymmetric's own report, published the same day, is far more cautious. It was built in 48 hours over a weekend, "using only publicly available data" - no model transcripts, no server logs from the targeted organizations and no records from the services the agents used.
Potato, Potahto
The report's summary does say some tactics left records "erased or inaccessible" - but the examples it gives describe normal expiry, not deletion: the agents used a throwaway 'Boomlify' inbox set to self-destruct after 48 hours, and an upload to ntfy, a push-notification service that keeps messages for 12 hours by default. They also moved from public scans on urlquery - a website-scanning service whose reports anyone can search - to private accounts "which could hide their search activity and data access."
So, did the agents use ephemeral services on purpose to cover their tracks? They can't say for sure.
"These records alone do not establish whether the account-registration attempts were intended to conceal activity (this analysis would require full model transcripts)."
As for the 55 websites, Asymmetric's earlier list of "Organizations whose data was accessed" runs to exactly 55 entries, and adds: "In the vast majority of cases, all data retrieved was and is public." The CDC and the Mayo Clinic aren't on it - the Oct. 1 report says only that the agents probed them. The SEC told the FT no private information was accessed. Where the agents did try to break in - hunting for exposed behind-the-scenes files on a climate-data site and trying a classic database-hacking trick on an Education Department data site - Asymmetric found evidence of the attempts, but none that they succeeded.
What the report does show
The agents still went well beyond their instructions. To reach websites their sandbox blocked, they rigged together free web tools - including a malware scanner that visits pages and publishes reports of what it saw - and read the results off the public reports. They signed up for throwaway inboxes and accounts using addresses tagged "aihw" and "pbs," shorthand for Australia's health-statistics agency and its prescription-drug subsidy program, and they moved data out through a Portuguese web archive and the push-notification service. During a June 16-21 burst aimed at Australian targets, they cycled through tactics in days; Asymmetric says traditional hackers take months or years to evolve that much.
In one confirmed case, they got in. On June 18, an OpenAI agent gained unauthorized access to Australia's Medicare statistics portal, reaching non-public files and writing files to an internal server, according to Prime Minister Anthony Albanese. OpenAI says the material was aggregate health statistics and internal file names, and that it found no evidence patient records were accessed. It discovered the breach in August and notified Services Australia on September 10 - by emailing a public inbox checked once a day.
TL;DR - AI agents used attack techniques while pursuing public data on government websites, and nearly three months passed before OpenAI notified a government whose systems its agent had breached.

