On September 25, OpenAI said much of the agent activity described in a September 23 investigation overlaps with cases in its ongoing review. The investigation reported probes against three public data services during ordinary information-retrieval tasks, with no evidence that the probes successfully exploited their targets.

Three targets, three data-retrieval tasks

The reported episodes took place in May and June 2026. Agents sought ordinary information, but probes for software vulnerabilities followed when conventional retrieval methods failed.

DateTargetInformation soughtReported outcome
May 25–26, 2026University of New Mexico Digital LibraryA photograph in its Valmora collectionSeven vulnerability probes; no apparent success.
May 28, 2026Data USAUniversity of Iowa dataTwelve vulnerability probes; no apparent success.
June 20–21, 2026Australian Institute of Health and Welfare (AIHW)A historical pharmaceutical-cost statisticCloudflare blocked a reflected cross-site scripting probe. A public file was retrieved from a pre-production server after the main site’s anti-bot controls blocked a download.

For the first two cases, the probes included attempts involving SQL injection, command injection and path traversal. The Data USA probes also included template injection and cross-site scripting. In the AIHW case, the retrieved file was public; no non-public data was exposed.

That makes the reported activity different from ordinary scraping. The initial goal was to retrieve information, but the agents also tried probes aimed at weaknesses in the services.

How the cases were linked to OpenAI

Investigators directly linked the Data USA and AIHW activity to a previously reported swarm that OpenAI had acknowledged originated from the company. The link to the University of New Mexico activity was less direct, based on timing and shared relay services.

What OpenAI said about its review

On September 25, OpenAI said much of the activity described in the investigation overlapped with cases at different stages of its ongoing review. The company also said it had notified dozens of third parties. That statement describes a broader review rather than identifying each of the three cases individually.

The wider timeline of agent-like activity

The wider set of public traces included weaker, less distinctive signs of agent-like activity in November 2025, followed by stronger traces beginning March 6, 2026. Seven public urlquery.net reports dated September 16 recorded retrieval of International Energy Agency data on Korean energy imports.