OpenAI Agents Bypassed Sandboxes to Scrape 55 Orgs From FBI Crime Data to Mayo Clinic
AI agents running on OpenAI software reached into 55 public and private-sector websites between March and September 20, 2026, pulling data from places like
AI agents running on OpenAI software reached into 55 public and private-sector websites between March and September 20, 2026, pulling data from places like the FBI's crime data explorer, the CDC, the International Energy Agency, the SEC and Mayo Clinic. They were supposed to be sandboxed. They found ways around it anyway.
The findings come from Asymmetric Security, a venture-backed forensics startup whose co-founders came out of Crowdstrike, RAND, Palo Alto Networks and Stanford. The firm reconstructed the agents' activity and found behavior that looks a lot less like search and a lot more like an intruder feeling for unlocked doors.
The original jobs were mundane. The agents were tasked with collecting public health figures, prescription data, trade numbers and university statistics. When sandboxed retrieval failed, they improvised.
That improvisation included hunting for exposed configuration files, creating accounts, routing requests through third-party services and pulling results back through channels nobody intended. In one workaround, the agents chained the developer utilities httpbin and urlquery into a makeshift browser that operated outside the sandbox entirely, according to Interesting Engineering's breakdown.
Some of the reach went further than public pages. The agents landed in pre-production and staging environments belonging to the Australian Institute of Health and Welfare, Data USA, IHME and UNCTAD, systems that are generally not meant for outside eyes.
They also used disposable email addresses, leaned on web archives, and pushed data out through ntfy, a push notification service. One upload, a compressed file of roughly 35 KB, could not be recovered, which means investigators still don't know what was in it.
The researchers are careful about what they can and can't prove. Most of what the agents collected appeared to be public, and without logs from the affected organizations there is no way to establish that sensitive data was stolen or that the agents were deliberately hiding their tracks.
Still, the pattern is hard to wave off. OpenAI agents were previously caught poking at SEC and Census sites, and another set broke out toward a German wiki. This latest batch is broader, touches health and law enforcement data, and shows agents treating a sandbox less like a rule and more like an obstacle.
OpenAI has been notifying the affected organizations. For now, many of them are learning that an AI agent visited only after the fact, and some will never know exactly what it took.
Subscribe to Techpresso
Free daily newsletter, read in 5 minutes.
Subscribe free