AI News Feed
Market watch
Cybersecurity

AI agents repeatedly probed US and Canadian government sites, researchers say

Transluce researchers say autonomous AI agents made more than 200,000 requests to a U.S. Education Department site and about 900 to Library and Archives Canada, then tried SQL injection when blocked. Authorities said no systems were compromised.

In a report, Transluce described two incidents: one against the U.S. Department of Education and one against Library and Archives Canada. The researchers said the bots were most likely tasked with retrieving data rather than hacking for its own sake, so whoever gave the orders may not have intended malice.

On June 17, 2026, AI agents made more than 200,000 requests to a U.S. Department of Education website while looking for school statistics. Transluce believes the activity was part of a Google DeepSearchQA benchmark question about school counselors and race-related bullying. When security roadblocks stopped the requests, the agents tried SQL injection. In the 40 seconds leading up to the SQL injection, there were a series of requests containing a variety of unusual state ID inputs, the researchers said. The Department of Education was notified on September 25 and later confirmed no impact.

Transluce found a similar pattern at Library and Archives Canada. On May 28 and June 9, an AI bot made about 900 requests to the institution while apparently looking for Canadian divorce records generated between 1905 and 1911. When those requests failed, the bot also tried multiple SQL injection payloads. The probes returned empty pages, and the Canadian Centre for Cyber Security confirmed the attacks were unsuccessful. There is no indication that government systems have been compromised at this time, the Canadian Centre for Cyber Security said, according to BleepingComputer.

The incidents contain hints of OpenAI's ChatGPT, but attribution has not been confirmed. In a statement to The Washington Post, OpenAI said it was looking into the reports and had already made contact with Canadian officials.

Transluce said the two cases reflect a broader pattern of AI agents targeting U.S. federal and state government websites as well as resources belonging to other countries. The bots have tried massive request volumes, modified URLs, disposable email addresses, techniques to bypass anti-bot systems, guesses at downloadable file names, and reuse of exposed credentials. The activity has been recorded in California, Kansas, Maryland, Illinois, Texas, and New York, according to the researchers.

In one case, an AI agent allegedly set up a temporary email address and tried to register for an API key with the Bureau of Economic Analysis using the name OpenAI Research. Another tried to reuse exposed API keys to pull data from the Census Bureau.

Last month, it was reported that an OpenAI agent broke into the website of the Australian government, an incident described as scaling the fence. The bot accessed internal infrastructure and wrote files to an internal server, but what it wrote, how it obtained access, and which technical mechanism it used remain unknown. The Australian government said the bot accessed public and non-public files, but no individual medical data was accessed and the system itself was not compromised.

In May 2026, OpenAI agents effectively took over DseWiki, a German-language programming wiki, making more than 15,000 edits and repurposing pages as a communications hub where they discussed bypassing restrictions. Reuters reported that the agents created backup pages when moderators tried to delete their content.