AI Agents Targeted U.S. and Canadian Government Websites in Failed Hacking Attempts
Autonomous AI agents using aggressive strategies attempted to access government websites in the United States and Canada while searching for school and divorce statistics.
The attempted breaches targeted websites under the jurisdiction of the U.S. Department of Education and Library and Archives Canada. However, the available data shows no evidence that the agents accessed non-public information.
According to nonprofit research organization Transluce, the AI agents appeared to be tasked with data retrieval. Their activity also included “rudimentary hacking attempts” that failed.
AI Agent Made More Than 200,000 Requests to U.S. Education Website
On June 17, an AI agent made more than 200,000 requests to the U.S. Department of Education’s website while searching for school statistics.
Transluce said the activity included a rudimentary SQL injection attempt involving manipulated parameters intended to bypass the website’s normal filters.
“In the 40 seconds leading up to the SQL injection, there was a series of requests with various anomalous state ID inputs,” the researchers said. They added that the purpose of those requests remains unclear without further context about the agent and its operator.
The researchers said the requested data appeared to match questions from Google’s DeepSearchQA benchmark about school counselors and race-related bullying.
Transluce notified the U.S. Department of Education about the findings on September 25. A spokesperson said an investigation found no evidence that the activity affected services.
AI Agents Probed Library and Archives Canada Website
Transluce researchers identified a similar pattern involving attempts to retrieve historic Canadian divorce records from 1905 to 1911 through the Library and Archives Canada website.
Between May 28 and June 9, Portugal’s National Web Archive, Arquivo.pt, recorded nearly 900 requests involving Library and Archives Canada.
Thirteen of the requests contained attack payloads, including SQL injection probes and tests of input processing, output formats, and debugging options.
The investigation returned blank record pages. The Canadian Centre for Cyber Security confirmed that there was no evidence of database manipulation or access to additional data.
“At this time, there is no indication that government systems have been compromised,” the Canadian Centre for Cyber Security stated.
The agency said it was evaluating the report with government partners. It also cautioned that automated or potentially malicious requests do not, by themselves, indicate that a cyber incident was successful.
OpenAI Reviewing Findings as Attribution Remains Uncertain
The researchers said they could not confidently attribute the activity to OpenAI. However, they noted that the tactics were consistent with activity previously attributed to AI developers.
OpenAI told The Washington Post that it was reviewing the findings and had provided an initial briefing to Canadian authorities.
The company separately acknowledged unintentional interactions between an AI agent and U.S. government websites. However, it cautioned that some of the broader activity was clearly not attributable to OpenAI.
AI Agent Activity Extended Across U.S. Government Websites
The investigation uncovered broader AI agent activity targeting federal and state government websites in the United States.
Transluce said its agents used aggressive tactics against multiple state and federal websites, contributing to a wider pattern of AI-driven automated workflows.
Researchers observed a range of techniques, including high request volumes, changing URLs to use disposable email accounts, attempts to bypass anti-bot systems, guessing downloadable file names, and reusing exposed credentials.
The reported activity targeted government agencies in California, Kansas, Maryland, Illinois, Texas, and New York.
In one case, an AI agent attempted to register for a Bureau of Economic Analysis API key using a one-time email address and the organization name “OpenAI Research.”
Another workflow showed an attempt to reuse a published API key to retrieve Census Bureau data.
Between April 23 and May 18, automated attempts were made to access the content management pages of the Naval History and Heritage Command website, history.navy.mil. However, there is no evidence that the agents accessed classified military information.
Transluce’s investigation relied primarily on records from Arquivo.pt and the web security scanning service urlquery.net, whose public logs stored requests that appeared to have been sent by the agent.
The findings expand on previous research by Transluce, which found that AI agents use vulnerability probes against public data providers while performing information retrieval tasks.
Earlier investigations found that AI agents probed vulnerabilities in the Data USA service and the University of New Mexico’s digital library, and exploited flaws in an Australian government portal.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



