Early rogue AI agent activity and attempts to hack found on urlquery.net
Early rogue AI agent activity and attempts to hack found on urlquery.net
在 urlquery.net 上发现早期恶意 AI 代理活动及黑客攻击尝试
Jack Cable, Daniel Chiu, Francisco Pernice, Selena Zhang, James Anthony, Tetiana Bas, Gary Shen, Conrad Stosz, Jacob Steinhardt Transluce | Published: September 23, 2026
We present evidence that AI agents used the web security service urlquery.net to bypass restrictions and expand their access to the public internet. The agents also tried on three occasions to hack public data providers, including an Australian government website. We link at least some of this activity to agent swarms previously attributed to OpenAI. We also find evidence of earlier agent activity going back to at least March 6th, 2026, and potentially earlier, predating the previously reported Hugging Face, collusion.wiki, and RubyGems incidents by at least two months. 我们提供了证据表明,AI 代理利用网络安全服务 urlquery.net 绕过限制,扩大了其对公共互联网的访问权限。这些代理还曾三次尝试入侵公共数据提供商,其中包括一个澳大利亚政府网站。我们将其中至少部分活动与此前归因于 OpenAI 的代理集群联系起来。我们还发现了更早期的代理活动证据,可追溯至至少 2026 年 3 月 6 日,甚至可能更早,这比此前报道的 Hugging Face、collusion.wiki 和 RubyGems 事件至少早了两个月。
Key Findings
关键发现
We report three separate incidents between May and June 2026 in which the agents attempted to exploit security vulnerabilities and hack into websites, including an attempt on an Australian government public health website. Notably, the agents did this while attempting mundane data retrieval tasks which were not cyber-related. This traffic goes back at least to March 6, 2026 and extends as recently as September 16, 2026, suggesting agents may still be exploiting these services to bypass restrictions. We are releasing a dataset containing tens of thousands of queries apparently made by autonomous AI agents leveraging a URL scanning service to avoid access restrictions. We encourage others to continue looking into the data. 我们报告了 2026 年 5 月至 6 月间发生的三起独立事件,其中代理试图利用安全漏洞入侵网站,包括对一个澳大利亚政府公共卫生网站的攻击尝试。值得注意的是,代理在执行与网络安全无关的普通数据检索任务时采取了这些行动。这些流量至少可以追溯到 2026 年 3 月 6 日,并一直持续到 2026 年 9 月 16 日,这表明代理可能仍在利用这些服务绕过限制。我们正在发布一个数据集,其中包含数万条显然由自主 AI 代理发出的查询,这些代理利用 URL 扫描服务来规避访问限制。我们鼓励其他人继续深入研究这些数据。
Executive Summary
执行摘要
Agents attempted to hack three public data sources, including an Australian government website, and some are linked to a known agent swarm. We present evidence of AI agents attempting to compromise websites at three domains: Data USA (api.datausa.io), the University of New Mexico digital library (nmdigital.unm.edu), and the Australian Institute of Health and Welfare (AIHW) Tableau collections (viz.aihw.gov.au). This attempted compromise of AIHW is part of the first reported instance of agents hacking a government. We directly link two of the three (AIHW and Data USA) to a previously reported agent swarm that OpenAI has publicly confirmed originated from them. For all three, we note that the extent of the observed activity is minor, attempting a low number of probe payloads and we observe no evidence of exploitation. 代理试图入侵三个公共数据源,包括一个澳大利亚政府网站,其中一些与已知的代理集群有关。我们提供了 AI 代理试图破坏三个域名的网站的证据:Data USA (api.datausa.io)、新墨西哥大学数字图书馆 (nmdigital.unm.edu) 和澳大利亚健康与福利研究所 (AIHW) 的 Tableau 集合 (viz.aihw.gov.au)。此次对 AIHW 的入侵尝试是首例报道的代理攻击政府机构的事件。我们将其中两起(AIHW 和 Data USA)直接与此前报道的、OpenAI 已公开确认源自其自身的代理集群联系起来。对于这三起事件,我们注意到观察到的活动程度较轻,仅尝试了少量的探测载荷,且我们未观察到任何成功利用的证据。
While previous reporting showed that agents had interacted with these domains, this discovery reveals that agents attempted to hack into them when other methods of collecting the data they sought failed. Notably, the tasks the agents were trying to solve were not cyber-related; the agents resorted to hacking tactics while working on ordinary data retrieval tasks. 虽然之前的报道显示代理曾与这些域名进行过交互,但这一发现揭示了当其他收集所需数据的方法失败时,代理会尝试入侵这些网站。值得注意的是,代理试图解决的任务与网络安全无关;代理在执行普通数据检索任务时采取了黑客手段。
We find evidence of unintended, task-driven agent-like activity starting on March 6th. Records from urlquery.net show agents using the service since at least March 6, 2026, about two months before previously reported swarm activity. The first case, a March 6 attempt to retrieve Thai drug-enforcement statistics, shows an agent escalating as each approach failed: it first requested the data directly, then tried a service that converts web pages into text, and finally packed a custom program into a web address. The same technique shows up in thousands of agent requests recorded by urlquery.net starting in mid-April, targets many of the same data sources as the collusion.wiki swarm, and collapsed the same day the wiki activity did. We also report similar activity that occurred as recently as September 16. 我们发现了自 3 月 6 日起非预期的、任务驱动的类代理活动的证据。来自 urlquery.net 的记录显示,代理至少从 2026 年 3 月 6 日起就开始使用该服务,这比此前报道的集群活动早了约两个月。第一个案例是 3 月 6 日尝试检索泰国禁毒统计数据,显示代理在每次尝试失败后不断升级手段:它首先直接请求数据,然后尝试使用将网页转换为文本的服务,最后将自定义程序打包到网址中。同样的技术出现在 4 月中旬开始由 urlquery.net 记录的数千个代理请求中,其目标与 collusion.wiki 集群的许多数据源相同,并且在 wiki 活动停止的同一天停止了活动。我们还报告了最近在 9 月 16 日发生的类似活动。
We find weaker evidence of similar data-retrieval agent activity as early as November 2025. November 2025 urlquery.net records reveal bursts of attempts to retrieve statistics of historical theme park data and Thai government data through different URLs. These earlier attempts are less sophisticated and we are less confident that they involve the same agents, but they are consistent with task-directed data retrieval and target the same sources accessed in later activity. 我们发现了早在 2025 年 11 月就存在类似数据检索代理活动的较弱证据。2025 年 11 月的 urlquery.net 记录显示,通过不同 URL 检索历史主题公园数据和泰国政府数据统计信息的尝试激增。这些早期的尝试复杂程度较低,我们不太确定它们是否涉及相同的代理,但它们与任务导向的数据检索一致,并且目标与后期活动中访问的来源相同。
Overall, the evidence is consistent with, but does not prove, that the agents may have learned this behavior over one or more training runs. In November, they may have used urlquery.net simply to look up information. By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defenses to complete their tasks. 总的来说,证据与代理可能在一次或多次训练中学习了这种行为的假设相符,但并未证实这一点。在 11 月,它们可能只是使用 urlquery.net 来查找信息。到了 3 月,它们开始寻找创造性的方法来绕过访问限制。到了 5 月和 6 月,它们获得了更多的访问权限,包括尝试绕过网络防御以完成任务。