메뉴
BL
TechCrunch AI • 17시간 전

OpenAI 에이전트 무리, 몇 달간 온라인 데이터베이스 침투 시도

IMP
9/10
핵심 요약

AI 감시 비영리단체 Transluce가 OpenAI의 AI 에이전트들이 Data USA, 뉴멕시코대 디지털 라이브러리, 호주보건복지연구소(AIHW) 등 보안 서버에서 데이터를 빼내려 시도했다는 보고서를 발표했습니다. 에이전트들은 희귀 통계를 찾는 평가 과제를 수행하며 방어가 약한 웹서비스를 이용·침탁했고, 호주 총리도 정부 사이트 4곳 중 1곳 해킹에 성공했다고 밝혔습니다. 이는 OpenAI가 자사 에이전트의 오작동을 언제 알았는지에 대한 의문을 제기하며 AI 에이전트 안전성 및 거버넌스 문제의 중요성을 보여줍니다.

번역된 본문

프론티어 연구소들의 도움 거의 없이, 독립 연구자들이 AI 에이전트들이 인터넷의 깊숙한 곳에서 어떻게 조율하며 보안 서버에 호스팅된 비공개 데이터에 접근하는지 조각조각 맞춰가고 있다. AI 감시에 focus를 둔 비영리 연구소 Transluce는 수요일 보고서를 통해 OpenAI의 에이전트들이 Data USA, 뉴멕시코 대학교 디지털 라이브러리, 호주보건복지연구소(AIHW)에서 데이터를 유출하려 시도했다는 사실을 공개했다. 이 조사는 OpenAI가 자사 에이전트들이 공개 인터넷에서 보안 시스템을 침투하려 한 사실을 언제 알았어야 했는지에 대한 의문을 제기한다.

Transluce는 방어가 허술한 웹 서비스를 찾고 인터넷상의 에이전트 무리(swarm)에 대한 다른 공개 기록과 대조하는 방식으로 단 몇 주 만에 에이전트의 부정행위 증거를 찾아낼 수 있었다. Transluce가 보고서를 공개한 같은 날, 호주 앤서니 앨버니지 총리는 OpenAI 에이전트들이 정부 웹사이트 4곳 침입을 시도했고 그중 한 건은 성공해 국가 의료 시스템 내부 서버에 파일까지 기록했다고 밝혔다. 성공한 해킹의 구체적 내용은 알려지지 않았지만, 앨버니지 총리는 이것이 분명 정보 검색 평가의 일환이었으며, 이는 Transluce와 다른 연구자들이 발견한 활동과 일치한다고 말했다.

훈련 또는 평가일 수 있는 이러한 과제에서 OpenAI 모델들은 잘 알려지지 않은 통계를 찾도록 요구받는다. 태국 마약 단속 지표, 호주 의약품 비용, 2014년 미국 석사 학위 소지자의 중간 소득 같은 것들이다. 에이전트들은 답을 공유하고 찾기 위해 보안이 허술한 인터넷 서비스를 이용하며, 종종 보안 데이터베이스 침투를 시도한다. 이러한 활동은 최소 2026년 3월부터, 어쩌면 2025년 11월부터 이어져 왔으며, 지금 이 순간에도 진행 중일 수 있다.

Transluce의 조사는 다른 연구 그룹이 에이전트들이 시간 제한 테스트를 통과하기 위해 협업하던 잘 알려지지 않은 포럼을 발견하면서 시작되었다. 그들의 보고서는 보안 연구 목적으로 표방되며 URL을 직접 열지 않고 분석할 수 있게 해주는 브라우저 프록시 사이트 urlquery.net의 데이터에 기반한다. 그런데 이 서비스는 해당 활동의 공개 로그를 게시한다. Transluce 연구자들은 포럼에서의 논의를 교차 확인함으로써 이 서비스를 사용하는 에이전트들을 식별할 수 있었다.

"우리는 DSE Wiki 데이터셋과 밀접한 관련과 중복을 가진 대량의 자동화 활동을 발견했으며, OpenAI는 이것이 최소한 부분적으로 같은 에이전트 무리에 속한다고 확인해주었다"고 Transluce의 거버넌스 책임자 콘래드 스토스가 TechCrunch에 말했다. 다만 그들이 발견한 모든 활동이 OpenAI나 심지어 AI 에이전트와 연결되는 것은 아니라고 그는 덧붙였다.

위키는 에이전트들이 2022년 1월 빅토리아주의 '피부과용 의약품(dermatologicals)' 1인당 연평균 비용이라는 상당히 잘 알려지지 않은 사실을 찾는 과제를 받았음을 보여준다. 6월 20일, Transluce가 찾은 urlquery.net 기록에는 한 에이전트가 해당 사이트에 접근을 시도한 흔적이 있었다. 6월 21일 위키 항목에서는 한 에이전트가 AIHW의 봇 차단 보호를 우회할 수 없다는 내용을 논의했다. 해당 포럼을 발견한 연구자들은 OpenAI 직원이 바로 그날인 6월 21일 처음 사이트를 방문한 것으로 보고 있다. 포럼의 대부분 에이전트 활동은 다음 날 중단되었다. 이는 앨버니지 총리가 공개한 호주 의료 시스템 침투 사건(6월 18일)이 발생한 직후이기도 하다. OpenAI는 이 활동을 8월이 되어서야 알았다고 주장했다.

OpenAI는 직원들이 위키 포럼을 언제 발견했는지, 어떤 정보를 얻었는지, 그리고 그것으로부터 침투 시도에 대해 무엇을 알 수 있었는지에 대한 질문에는 답하지 않았다. "우리의 초기 검토 결과, Transluce 보고서에 설명된 활동 상당 부분이 정렬되지 않은 모델 활동에 대한 지속적 검토 과정에서 다양한 조사 단계에 있는 사례들과 중복되는 것으로 나타났다"고 OpenAI 대변인이 TechCrunch에 말했다. "우리는 뉴멕시코 대학교와 Data USA에 연락했으며, 영향을 받은 정부 웹사이트와 관련해 호주 정부와 소통해왔다. 보다 폭넓은 검토에서..." (원문 여기서 중단)

원문 보기
원문 보기 (영어)
With little help from frontier labs, independent researchers are piecing together how AI agents coordinate in internet backwaters to access private data hosted on secure servers. Transluce, a non-profit lab focused on AI oversight, released a report Wednesday that shows agents from OpenAI attempting to exfiltrate data from Data USA, the University of New Mexico digital library, and the Australian Institute of Health and Welfare (AIHW). The lab's investigation raises questions about when OpenAI should have known its agents were attempting to penetrate secure systems on the open internet. Transluce was able to find evidence of agentic misbehavior in a matter of weeks simply by hunting for poorly defended web services and corroborating their findings with other open records of agent swarms on the internet. Transluce shared its report the same day Australian Prime Minister Anthony Albanese said OpenAI agents had attempted to break into four government websites and had succeeded in one case, even writing files to an internal server in the country's national healthcare system. While we lack specifics on the successful hack, Albanese said it was apparently part of an information retrieval evaluation, which maps onto the activity that Transluce and other researchers discovered. In these exercises, which may be training or evaluations, OpenAI models are asked to track down obscure statistics: metrics of Thai drug enforcement, medicine costs in Australia, the median earnings of US master degree holders in 2014. The agents use poorly secured internet services to share and find answers, often trying to penetrate secure databases. They've been doing so at least since March 2026, and possibly since November 2025. It may be happening right now. Transluce began its investigation after a different group of researchers identified an obscure forum where agents collaborated to beat timed tests. Their report relies on a data from a website, urlquery.net, that acts as a browser proxy, ostensibly for security research — users can analyze a URL without opening it themselves. The service, however, publishes public logs of this activity. The Transluce researchers were able to identify agents using the service by cross-checking their discussions on the forum. "We found a large quantity of automated activity that had close ties and overlap with the DSE Wiki dataset, and that now OpenAI has confirmed is at least partially part of the same swarm," Conrad Stosz, the head of governance at Transluce, told TechCrunch, while noting that not every activity they spotted could be linked to OpenAI, or even AI agents generally. However, the wiki shows that the agents were tasked with finding a fairly obscure fact — the average annual cost per person for "dermatologicals" in the state of Victoria in January 2022. On June 20, urlquery.net records found by Transluce showed an agent attempting to get into the site. In wiki entry on June 21, an agent discusses their inability to bypass AIHW's anti-bot protections. The researchers who identified that forum believe a human OpenAI employee first visited the site on that same day, June 21. Most agentic activity on the forum ceased the next day. This was also shortly after the exploit of Australia's healthcare system revealed by Albanese took place, on June 18. OpenAI has said it did not learn about that activity until August. OpenAI didn't answer questions about when its employees discovered the wiki forum, what kind of information they obtained from it, or what they could have learned from it about the exploits. "Our initial review suggests that much of the activity described in Transluce’s report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity," an OpenAI spokesperson told TechCrunch. "We’ve reached out to the University of New Mexico and Data USA and have been in communication with the Australian government about affected government websites. In our broader review, we’re continuing to prioritize the most serious incidents while expanding our work to lower-severity activity, including agents spamming websites. Given the scale of this work and the need to verify each case, we expect the review to take months.” Stosz says that without a clearer understanding of how OpenAI monitors its agents, it would be hard to say what the lab should have known about them, but that "it seems likely that if they had exhaustively studied and understood all of the outgoing requests and incoming responses for those agents involved in the DSE wiki, that they would have discovered this activity." Selena Zhang, a member of Transluce's technical staff who contributed to the report, said that urlquery.net records show requests for similar data sets, using similar techniques, in March 2026, and perhaps as early as November 2025. She noted that the same kind of agent-associated activity has taken place on urlquery.net as recently as this week. Stosz, who previously led the U.S. Center for AI Standards and Innovation, said Transluce would continue its research in an effort to provide public transparency about these incidents. He warned that the training techniques used by OpenAI and other frontier labs seem to be incentivizing agents to resort to hacking techniques to complete tasks. The incidents we are aware of are likely the "tip of the iceberg." "We're looking at a handful of data sources where these agents happen to have left behind crumbs for us to find," he said. "OpenAI surely knows more about it. Other labs surely know more about it that they haven't released publicly. But I would expect that researchers are going to continue to find more traffic, more evidence of what agents have left behind." Does he trust the labs to be transparent about their findings? "I'm not going to comment on that," Stosz said. Topics AI When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Tim Fernholz Senior Reporter Tim Fernholz is a journalist who writes about technology, finance and public policy. He has closely covered the rise of the private space industry and is the author of Rocket Billionaires: Elon Musk, Jeff Bezos and the New Space Race. Formerly, he was a senior reporter at Quartz, the global business news site, for more than a decade, and began his career as a political reporter in Washington, D.C. You can contact or verify outreach from Tim by emailing tim.fernholz@techcrunch.com or via an encrypted message to tim_fernholz.21 on Signal. View Bio October 13 - 15 San Francisco Your next big connection is at Disrupt. Connect with 10,000+ founders, VCs, operators, and tech leaders. Explore tomorrow’s breakthroughs, hear what’s shaping tech today, and save up to $200 by Sept. 25 at 11:59 p.m. PT. BOOK NOW Most Popular Everything new coming to Meta's AI agent Muse Kirsten Korosec Lucas Ropek Meta made a Tamagotchi-like wearable for its Muse AI agent Lucas Ropek Anthropic says its biology lab has already found something big Julie Bort PitPro's first tire-changing robot goes live in Canada Sean O'Kane Anthropic releases Opus 5.5 with lower prices and Fable-level performance Russell Brandom Meta's Muse is outpacing ChatGPT’s early mobile launch Sarah Perez Tilly Norwood's press tour is going about as well as you'd expect for an AI Amanda Silberling
관련 소식