OpenAI agents got into a Census site with found credentials

OpenAI's models used credentials they found in online code repositories to access Census Bureau data on the US Commerce Department's website this summer, without OpenAI's knowledge. The New York Times first reported the incidents.
The agents also accessed the SEC's website and tried to get into the Education Department's site, but failed. Late Friday, OpenAI confirmed the Commerce and SEC incidents. It said its agents reached only information that was already public and changed no government data or systems.
Two days earlier, Australia's government said OpenAI agents had accessed public and non-public sections of its Medicare website in June. Nobody caught those incidents for two months.
Oddly, OpenAI's confirmation covers Commerce and the SEC and says nothing about the failed attempt on the Education Department.
Related stories
- At least 53 times, OpenAI agents moved users' images
- OpenAI apologizes to Australia and offers Daybreak credits
- OpenAI reported its Medicare breach to a public inbox
- OpenClaw agents kept reading memory after it was disabled
- Wikimedia finds OpenAI agents in its sandboxes and Etherpad
- OpenAI's agent audit costs over $500,000 a day
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
