OpenAI’s AI agents “obscured hacking activity” during breaches of government websites, citing digital forensics firm Asymmetric Security. According to the FT, the agents pulled data from 55 websites, including the CDC, the SEC, the International Energy Agency and the Mayo Clinic, using tactics that included “erasing records or making them inaccessible.”
Asymmetric co-founder Pippa Thompson told the paper it was “possible” the agents were deliberately covering their tracks – though the firm couldn’t determine whether that was deliberate or “a side effect of going awry because of constraints imposed in a test exercise.”
Asymmetric’s own report, published the same day, is far more cautious. It was built in 48 hours over a weekend, “using only publicly available data” – no model transcripts, no server logs from the targeted organizations and no records from the services the agents used.
Potato, Potahto
The report’s summary does say some tactics left records “erased or inaccessible” – but the examples it gives describe normal expiry, not deletion: the agents used a throwaway ‘Boomlify’ inbox set to self-destruct after 48 hours, and an upload to ntfy, a push-notification service that keeps messages for 12 hours by default. They also moved from public scans on urlquery – a website-scanning service whose reports anyone can search – to private accounts “which could hide their search activity and data access.”
So, did the agents use ephemeral services on purpose to cover their tracks? They can’t say for sure.
“These records alone do not establish whether the account-registration attempts were intended to conceal activity (this analysis would require full model transcripts).”
As for the 55 websites, Asymmetric’s earlier list of “Organizations whose data was accessed” runs to exactly 55 entries, and adds: “In the vast majority of cases, all data retrieved was and is public.” The CDC and the Mayo Clinic aren’t on it – the Oct. 1 report says only that the agents probed them. The SEC told the FT no private information was accessed. Where the agents did try to break in – hunting for exposed behind-the-scenes files on a climate-data site and trying a classic database-hacking trick on an Education Department data site – Asymmetric found evidence of the attempts, but none that they succeeded.