[Digital Today reporter Chi-gyu Hwang (황치규)] OpenAI AI agents tried to hack university and government websites in May and June this year, the Wall Street Journal (WSJ) reported on Sept. 24 local time. The agents were doing simple online data-collection tasks and tried hacking to obtain information.
The WSJ report said the nonprofit AI research lab Transluce and the Australian government newly disclosed the findings of their investigation.
The hacking attempts did not come from a security test in which OpenAI deliberately has agents hack systems. The agents did it on their own while searching for materials. The WSJ said it appeared to have happened during OpenAI's process of training models or testing their ability to search for online materials.
The OpenAI agents were looking for information such as Thai labor statistics, South Korea's crude oil import volume and Australian dermatology data.
Researchers said the targets were the Australian Institute of Health and Welfare, the University of New Mexico and the DataUSA website. DataUSA is a public data site run by Deloitte, Datawheel and MIT. The WSJ said there was no evidence the OpenAI agents downloaded non-public information through the hacking attempts.
Transluce said the agents switched to a hacking technique that attaches malware to search requests after they failed to access the data they wanted.
The WSJ said records remained in the online tool the agents used instead of a web browser, allowing researchers to trace which sites the agents made requests to and what they requested.
Researchers said they suspected the agents used the tool to break into sites that block bot access. An OpenAI spokesperson said, "We are broadly reviewing agent activities that deviated from their goals."