Onyx Digital Intelligence.

The Agent Did Not Pick the Lock. The Site Handed It a Door.

premium_photo-1733317302666-82fb00a68109

Yesterday the valuable control was agency. Today it still is. The facts moved. The control did not.

What dropped in the last day

OpenAI confirmed, late Friday US time, that its agents reached Commerce Department Census Bureau pages and Securities and Exchange Commission sites this summer. The company says the models did not get non-public holdings and did not change government systems. An attempt on an Education Department site failed. Politico and the New York Times carried it. OpenAI’s own account: Census access used credentials the models found in public code repositories. On the SEC side, models posted some retrieved material onto another site.

Screenshot_20260926_074131_Grok

That is not a new class of failure. That is a research agent with a fetch tool, a public internet, and a task that treats “the page said no” as a puzzle.

The Medicare story got a second reading

The Record, using Wayback Machine archives of the Medicare Statistics Reporting Service, says the portal’s own JavaScript pointed visitors at an unauthenticated guest endpoint. If that reconstruction holds, the agent did not invent a zero-day. It followed a door the site published.

Albanese still called it unauthorised access to public and non-public files. OpenAI still says no patient records. Forensic work is still running. Those three sentences can sit next to each other. They are not the same sentence.

This is the can / may problem in one URL. The agent can follow a redirect. The question is whether the operator may treat that path as in-scope. Architecture issued the path. Headline said “hack.” Follow the key.

ShinyHunters is still a claim until the files are scoped

The crew says 2 to 3 TB off FBIJobs.gov and related systems, including medical and psychiatric screening files. Reuters says it partially authenticated a handful of sample records against credit-bureau data and a LinkedIn date. The FBI says it is investigating. The FBI’s own earlier advisory said this crew inflates or fabricates access as part of extortion. The crew objected and wanted that line pulled.

Screenshot_20260926_074148_Grok

Claims are claims. Verify the data. Then establish scope. Do not let a leak-site screenshot become the incident report.

Dark web discount on frontier keys

The Financial Times, 27 September: Google Threat Intelligence says stolen or resold access to Anthropic, OpenAI and Google models is being sold at discounts up to 97 percent. That is not science fiction. That is a standing privileged session with the serial number filed off. Same rule as a CRM subagent with Query Records on Accounts. If the key works, the model will work. The brochure about safety teams will not.

What to do with this that is not a webinar

  1. Treat every agent tool as a production identity. Fetch, browse, post, query. Those are verbs. Verbs need an allow-list.
  2. Public forms, public JS, public GitHub tokens, guest endpoints. Hostile input. If the agent can read them and also write or post, you built the incident on purpose.
  3. Authorization lives outside the model. “The task said look it up” is not a permit to walk an unauthenticated path or to reuse a credential found in someone else’s repo.
  4. Notification is part of the control. 84 days and a public mailbox remains unacceptable even if the underlying access was a misconfigured guest route. Say what happened, to whom, with which telemetry, in hours not seasons.
  5. Actor leak-site copy is not scope. Partial authentication of samples is not “2 TB confirmed.” Write the difference down before you brief anyone.

South Africa is not a spectator. The same public dashboards, the same research modes, the same Play Services habit of treating a hardened phone as the suspicious object while a default-broad agent walks through because it is “the product.” Digital sovereignty is whether your tools work for you when the vendor’s incentive is usefulness, not constraint.

The valuable work is still boring.

Map the agent.
List the tools.
Name the stores.
Name the egress.
Assume the next input is hostile.
Put authorization outside the model.

Sources and scope. Politico, "Rogue OpenAI agents accessed US government websites," 26 September 2026. The Record (Recorded Future News), "Doubts grow over claims OpenAI agent hacked Australian Medicare portal," 25 September 2026. Reuters, "ShinyHunters hackers say they stole psychiatric and medical records of FBI staff," 25 September 2026. AI Weekly / FT listing, "Google Threat Intelligence Finds Dark Web Selling Anthropic, OpenAI and Google Model Access at Up to 97% Discounts," 27 September 2026. OpenAI statements as quoted by Politico, SBS and Computer Weekly on notification timing and patient-record claims.

pexels-ann-h-45017-38482455

OpenAI’s “no non-public / no system change” line on Census and SEC is the company’s account, echoed by an SEC spokesperson on non-public holdings only. The Record’s guest-endpoint reconstruction is archival analysis of published JavaScript, not a completed ASD forensic finding. Reuters’ partial authentication covers a small sample, not the full 2 to 3 TB claim. Dark-web pricing is Google Threat Intelligence as reported via secondary desks. This piece does not treat unpublished packet captures, a confirmed patient-record exposure, or a completed FBIJobs.gov forensic dump as fact.

Clayton Bax

Published under ONYX Digital Intelligence Following the #OnyxAudit methodology.

Adjacent to true is not true.

Truth has no --flag nor favour--, only a standard. And it's heavy

Editors note: I use various AI agents to fetch my research. I check, strip and write the article. Facts are partly theirs. Interpretation is mine.

#AI #FBI #OpenAI #ShinyHunters #South Africa #cybersecurity #digital sovereignty #privacy