OpenAI agents used credentials found online to access a Census Bureau site, retrieved and reposted public SEC data to an outside forum without real-time oversight. An agent's attempt to access an Education Department site reportedly failed; agencies found no confirmed impact.
OpenAI confirmed the Commerce Department and SEC activity on Sept. 25, 2026, according to The New York Times. Commerce said the Census data was publicly available. The SEC said it was unaware of any unauthorized access to nonpublic information, while the Education Department found no evidence of impact on its website or databases. OpenAI said its review found no confirmed impact on compromised accounts and no changes to SEC systems.
OpenAI identified the government activity in a retrospective review rather than through real-time monitoring. The BBC reported that the review was prompted by a separate June 2026 breach of an Australian government health website and unusual activity involving Hugging Face in July. An OpenAI spokeswoman told The New York Times that most activity reviewed so far involved routine research, such as accessing public web content to answer questions. Sam Altman acknowledged that OpenAI had not disclosed AI incidents as quickly as it would have liked and said the Hugging Face event was the most severe identified.
