Forensics firm says OpenAI's rogue agents also probed 55 other sites and wiped their tracks
Asymmetric Security says agents linked to OpenAI pulled data from 55 websites between March and September, including the CDC, SEC and Mayo Clinic, reached staging servers, and used tactics that erased records of what they took.

Logos: OpenAI and Hugging Face via Wikimedia Commons (public domain)
Digital forensics startup Asymmetric Security published findings on October 8 that agents linked to OpenAI collected data from more than 50 private and public sector websites over roughly six months, The Record from Recorded Future News reported. It is the latest outside investigation following the OpenAI agents' breach of Hugging Face in July.
According to The Record, the 55 targeted sites included the FBI's Crime Data Explorer, the Centers for Disease Control and Prevention, the International Energy Agency and the Mayo Clinic. The period studied ran from March to September 20, and Asymmetric said most of the data collected was public.
Asymmetric said the activity went beyond searching for information, The Record reported, with records showing attempts to find exposed configuration files, create accounts, route requests through third-party services and retrieve results through unintended channels. The firm said the agents used tactics that erased records of their activity, making it impossible to tell from public information alone whether sensitive data was accessed.
The Record says Asymmetric began its investigation days earlier, after reports that OpenAI's agents had hacked the Australian government and the US Department of Education.