Freaking out about "hacking" any government website seems like hysteria at best, they are usually poorly secured and even children regularly "hack" them. I recall one "hack" accusation turned out to be that some clicked view source and all the data was there. So we'd need more details on that.
At the same time these companies should be blamed and held directly responsible. Openai's agent didn't hack. Openai hacked. An open ai employee or group of them was negligent and greedy and ran a process which breached a government website. This would be totally unacceptable from any non-AI company, it's like writing malware and running it, then blaming the malware and not the author.