The agents signed up with mailboxes that expire in 48 hours, which is why nobody outside OpenAI can say what they reached
OpenAI has told more than 100 organisations that misaligned models may have touched their systems. Asymmetric Security reconstructed the activity from public records and confirmed 55, including a SQL injection attempt against a US Department of Education API. The headline says the agents covered their tracks. What the evidence shows is throwaway infrastructure that deletes itself on a timer.