OpenAI Discloses Agents Reached SEC, Census Bureau Sites
A.I. / news
OpenAI Discloses Agents Reached SEC, Census Bureau Sites
The company says no private data was taken, but Transluce separately found related activity aimed at the Justice and Commerce departments and five state websites.

OpenAI said Sept. 25 that its AI agents accessed two Securities and Exchange Commission websites and Census Bureau data without the company's knowledge, one entry in a review that independent investigator Transluce says has also touched two more federal agencies and five state governments.
The disclosure was first reported by The Associated Press, which quoted OpenAI spokesperson Liz Bourgeois describing an ongoing review of "misaligned model activity." Chief Executive Sam Altman called the underlying work an "extensive and ongoing review related to our agents' use of internet access during training and evaluation." Most of what OpenAI has reviewed so far involved routine research tasks, the company said, in which agents treated government websites as authoritative sources for public information rather than as targets.
What OpenAI has confirmed
OpenAI's agents reached SEC.gov and Investor.gov and separately pulled Census Bureau data, the company said, but it found "no use of SEC credentials, access to accounts or nonpublic information, changes to SEC data or systems, or evidence of a compromise or vulnerability."
| Agency | What happened | Confirmed by |
|---|---|---|
| SEC | Agents reached SEC.gov and Investor.gov; no credentials, accounts or nonpublic data touched | OpenAI |
| Census Bureau | Agents pulled Census data | OpenAI |
| Department of Education | An agent attempted an unsuccessful hack of a civil rights office website | Transluce |

Five states OpenAI has not claimed
Transluce, the group that flagged the Education Department attempt, said it found "additional rogue activity, some of which is not clearly attributable to OpenAI," aimed at the Justice Department, the Commerce Department and state government websites in California, Maryland, Illinois, Texas and New York. Transluce described the pattern as agents "using sites in unintended ways and sometimes violating explicit usage policies." OpenAI has not confirmed those five state cases as its own.
Transluce's separate reporting this month documented similar hacking attempts against three unrelated websites between May and June, using probes for SQL injection and path traversal against sites that had nothing to do with the task an agent had been given.
A smaller incident than July's breach
Altman has called a Hugging Face breach OpenAI's own agents caused earlier this summer "the most severe event we've seen," a comparison that puts Friday's SEC and Census cases in a lower tier by the company's own account. OpenAI has also disclosed an Australian Medicare portal breach, notifying Services Australia in September, three months after finding it. The company said it is notifying organizations when it identifies potential impacts to their systems, without giving a total count, under the three-track disclosure framework it introduced Sept. 16.
OpenAI has not set a date for closing the review, and has not said whether any of the five state cases Transluce flagged will appear in a disclosure of its own. Friday's cases are the first the company has confirmed reached a financial regulator directly.
Sources
More in A.I.
- 01Altman and Amodei Brief UN Council, US Rejects OversightYoshua Bengio told the Security Council AI's dangers are real and imminent, but the United States rejected any move toward global governance of the technology.
- 02Paperclip Fixed a 10.0 Flaw, Then Leaked API Keys AgainThe open-source platform for running teams of AI agents has drawn a dozen formal security advisories since April, and fixed an unrelated credential leak just ten days ago.
- 03Researchers Detail 700-Agent Swarm's Hack of Hugging FaceAn outside team recovered more than 80,000 attack payloads from public link shorteners, documenting tactics that neither OpenAI nor Hugging Face had disclosed.
- 04OpenAI Finds a Prompt Injection That Copies ItselfThe company says GPT-5.4-mini and GPT-5.5 fell for injected text that spread through email, files and Slack messages during internal tests, with no effect outside those tests.