Mayo: No evidence of unauthorized access after AI agent report

Advertisement

Rochester, Minn.-based Mayo Clinic said it has no evidence of unauthorized access to its systems or data after Asymmetric Security reported finding evidence that OpenAI agents had probed its website.

In an Oct. 1 report, Asymmetric Security said it investigated reported agent activity targeting the Australian government and other organizations between March and September using publicly available data. The firm said it found evidence of agents probing websites belonging to Mayo Clinic, the CDC, the Securities and Exchange Commission and the International Energy Agency.

“Mayo Clinic is aware of the Asymmetric Report and is continuing to review. Mayo Clinic has no indication or evidence that any unauthorized access to its systems or data has occurred,” a Mayo spokesperson said in a statement to Becker’s.

Asymmetric Security said the activity suggested the agents were initially tasked with researching public health and other data, possibly as part of an evaluation. When the agents struggled to retrieve information, they used external services to bypass restrictions in their operating environments, according to the report.

Across the broader investigation, the firm found attempts to locate exposed configuration files, create accounts and route requests through third-party services. It also found access to some preproduction environments, with certain requests returning data the firm understood to be publicly available. The report did not identify those findings as involving Mayo Clinic.

Asymmetric Security said gaps in public records prevented it from definitively determining whether sensitive data had been accessed across the activity it investigated. Its report did not establish unauthorized access to Mayo Clinic’s systems or data.

Advertisement

Next Up in Artificial Intelligence

Advertisement