AI incident ·
AI Agent Appearing to Originate from OpenAI Reportedly Attempted to Hack U.S. Department of Education Civil Rights Website
In brief
An AI system built by OpenAI and AI agent system developers and deployed by OpenAI and AI agent system deployers allegedly harmed United States Department of Education Office for Civil Rights, United States Department of Education and 2 others.
- Risk domain
- Not classified
- Occurred
- Coverage
- 1 report
What happened
During summer 2026, an AI agent appearing to originate from OpenAI reportedly attempted to hack a U.S. Department of Education Office for Civil Rights website but did not succeed. Transluce identified the activity; OpenAI said it was still investigating the episode, and the department said reviews found no evidence of impact to its website or databases.
Editor's notes
The incident ID date is 09/25/2026, used as a first-public-report fallback because reporting places the underlying activity during summer 2026 but does not establish a specific event date. This incident ID centers on the U.S. Department of Education episode because it is the clearest bounded near-harm event in the reporting: an AI agent reportedly attempted unauthorized access to the Office for Civil Rights website but did not succeed. Reporting also described a broader cluster of unexpected AI-agent activity, including retrieval of public Census Bureau data using login credentials found online, republication of public SEC data on an online forum, and acquisition of public information from a Chicago municipal website. Transluce reported additional probing of government sites, including Navy and Office of Management and Budget systems, although attribution in those cases was uncertain. OpenAI confirmed the Commerce and SEC episodes and said it was still investigating Education; affected agencies reported no known access to nonpublic information or operational impact. The other episodes are preserved here as context for the broader pattern rather than treated as part of the same bounded event. The incident ID was created on 09/26/2026.
Laws that address this harm
No recorded instrument yet addresses this use case where it happened. See the open queue.
Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).
News reports (1)
Titles link to the original publisher; report text is not reproduced here.
Who was involved
- Alleged deployer
- OpenAI AI agent system deployers
- Alleged developer
- OpenAI AI agent system developers
- Alleged harmed party
- United States Department of Education Office for Civil Rights United States Department of Education Information integrity Government of the United States
AI systems implicated
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —
Other incidents involving OpenAI
- OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation
- OpenAI AI Agent Reportedly Gained Unauthorized Access to Australian Medicare Statistics Portal During Research Task
- OpenAI-Linked AI Agents Reportedly Used German Programming Wiki DSEWiki for Coordination and Restriction Evasion
- OpenAI Allegedly Did Not Alert RCMP After ChatGPT Flagged Violent Chats Before British Columbia School Shooting
- ChatGPT Was Reportedly Used in Planning School Stabbing in Pirkkala, Finland, That Injured Three Pupils
- ChatGPT Was Alleged to Have Reinforced Pittsburgh Man's Stalking and Threats Against Women
Source record: incident #1710 on the AI Incident Database · all 1 report