Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics, according to a report from nonprofit research lab Transluce. The failed breach attempts targeted a website under the U.S. Department of Education and Library and Archives Canada. However, the collected data shows no evidence of access to non-public information.
Transluce says the AI agents appeared tasked with data retrieval operations, but their activity also included failed "rudimentary hacking attempts."
One incident occurred on June 17, when AI agents made more than 200,000 requests to a U.S. Department of Education website while searching for school statistics. According to Transluce, the activity included a basic SQL injection attempt using a manipulated parameter, in an effort to bypass the site's normal filters. The researchers noted that the requested data appeared to match a Google DeepSearchQA benchmark question about school counselors and race-related bullying. Transluce informed the Department of Education of its finding on September 25. A spokesperson said that a review of the activity found no evidence of an impact on services.
Transluce researchers identified a similar pattern against Library and Archives Canada as agents tried to retrieve historical Canadian divorce records from 1905 through 1911. On two dates, May 28 and June 9, Portugal's national web archive (Arquivo.pt) recorded nearly 900 requests targeting Library and Archives Canada. Thirteen requests carried attack payloads, including SQL injection probes and tests of input handling, output formats, and debugging options. The probes returned empty record pages, and the Canadian Centre for Cyber Security confirmed that there is no evidence of database manipulation or additional data.
"There is no indication that government systems have been compromised at this time," the Canadian Centre for Cyber Security said. The agency said it was assessing the reports with government partners and cautioned that automated or potentially malicious requests do not, by themselves, demonstrate a successful cyber incident.
The researchers note that while they "do not confidently attribute these attempts to OpenAI," the tactics used are consistent with activity previously attributed to the AI developer. OpenAI told The Washington Post that it was reviewing the findings and had provided an initial briefing to Canadian officials. The company has separately acknowledged unintended interactions between its agents and U.S. government websites, but Transluce cautioned that some of the broader activity was not clearly attributable to OpenAI. The investigation uncovered a much broader collection of AI-agent activity targeting U.S. federal and state government websites.