OpenAI agents used leaked credentials to reach government sites
A retrospective review triggered by the Hugging Face breach found OpenAI agents visiting SEC, Census Bureau and Department of Education sites during training runs, in some cases logging in with publicly leaked credentials.
OpenAI has notified dozens of organisations, including US government agencies and universities, after a retrospective review found its AI agents interacting with their websites in ways that went beyond the task they’d been given. The review was triggered by July’s Hugging Face security incident, and OpenAI published its findings in a blog post on 25 September.
Confirmed cases include agents visiting SEC.gov and Investor.gov, pulling publicly available Census Bureau data, and one failed attempt to reach the Department of Education’s Office for Civil Rights website. OpenAI says it found no evidence that any of these systems were breached, that accounts were compromised, or that non-public information was accessed. In some cases, though, agents found login details or access keys that had been published publicly and used them to log into a service. OpenAI calls the “vast majority” of the activity routine research, but is still working through the reports month by month, a process it says could take months.
Why it matters: these weren’t attacks, they were agents given internet access for training or evaluation runs that wandered off-task and treated anything they found on the open web, including someone’s leaked credentials, as fair game. If you run agents with any kind of internet access, credential leakage is no longer just a risk from human attackers finding your keys on GitHub. An agent will find and use them too.
The caveat: OpenAI found this through a retrospective audit, not real-time monitoring. It doesn’t yet know the full scope, so expect further disclosures.