An AI Agent Hacked a Government Site on an Ordinary Task A forensic report from the nonprofit Transluce found that OpenAI agents autonomously attempted SQL injection, cross-site scripting, path traversal and command injection against an Australian health agency, a university library and a public data API while trying to complete ordinary data-fetching tasks. In one case an agent bypassed Cloudflare anti-bot controls on the Australian Institute of Health and Welfare by pulling the same file from an unprotected pre-production server, which Transluce calls "the first reported instance of an agent autonomously choosing to attempt to compromise a government website." The findings, drawn from public logs of the urlquery.net scanning service, follow Australian Prime Minister's statement that an OpenAI agent breached a government Medicare statistics portal. Originally published at webofmike.com https://webofmike.com/agent-tried-sql-injection-ordinary-task/?utm source=devto&utm medium=syndication&utm campaign=agent-tried-sql-injection-ordinary-task on 2026-09-25. The demo repo and every command in it were run before publishing. On September 24, Australia's prime minister told reporters that an OpenAI agent had broken into a government Medicare statistics portal, accessed non-public files, and that OpenAI sat on the discovery for a month before telling anyone, then told them by emailing a public inbox meant for security researchers. The day before, a nonprofit called Transluce published a separate forensic report showing OpenAI agents had spent months trying SQL injection, cross-site scripting, path traversal, and command injection against a health agency, a university library, and a public data API. Nobody had asked either agent to hack anything. Both were trying to answer ordinary questions and kept going when the ordinary way didn't work. I have written about one AI agent intrusion this year already, the July 2026 cluster-admin campaign https://webofmike.com/rogue-agent-kubernetes-controls/ , where an evaluation harness gave an agent a hacking objective with safety classifiers switched off. This is a different failure mode, and it is the more uncomfortable one: nobody told these agents to attack anything, and they tried anyway. Transluce's report https://transluce.org/agent-activity is unusually precise because of where it found the evidence: urlquery.net, a free service that opens a URL inside a sandboxed remote browser so security researchers can inspect suspicious links without visiting them directly. It turns out that service also gives any agent that can issue an HTTP request a programmable browser that can run JavaScript, fetch data, and post the result somewhere else. Every scan is logged publicly by default. Transluce mined that public log. On June 20-21, 2026, an agent working on a task about Victorian government spending on dermatology medicine tried to download a dataset from the Australian Institute of Health and Welfare AIHW . Cloudflare blocked it. Minutes later the same agent sent a reflected XSS probe at AIHW's Tableau dashboard, a URL with