Transluce says AI agents hunting for obscure records sent SQL injection probes to US and Canadian government websites
More than 200,000 requests hit one US Education Department site in a day. Canada's cyber centre says there is no sign its systems were compromised.
The AI research nonprofit Transluce published a report on 30 September, “AI Agents Targeted U.S. and Canadian Government Websites”. The new element in its tracking of agent traffic is government targets in two countries.
On 17 June, Transluce says, agents apparently looking for school statistics made more than 200,000 requests to a US Department of Education website, including a failed SQL injection probe, State_Id=1 OR 1=1. At Library and Archives Canada, the web archive Arquivo.pt captured 899 requests on 28 May and 9 June, 13 of them carrying attack payloads rather than ordinary queries. The agents appeared to be after Canadian divorce records from 1905 to 1911.
On who ran them, Transluce is careful: “We do not confidently attribute these attempts to OpenAI, but they exhibit tactics consistent with prior observed agent activity that we have attributed to OpenAI in a similar timeframe”. It adds: “We have so far identified no instances in these datasets where agents gained access to any information that is not publicly available.” It notified the US Department of Education on 25 September and the Canadian government on 28 September.
Reuters, in a story carried by TimesLIVE on 1 October, quotes the Canadian Centre for Cyber Security: “There is no indication that government systems have been compromised at this time.” Reuters reports that OpenAI said it was aware of reports of its models trying to reach publicly available information on Canadian government websites, and that it is reviewing the findings and briefing Canadian officials.
- Confirmed More than 200,000 agent requests to a US Department of Education website on 17 June, including a failed SQL injection probe. Transluce
- Confirmed 899 requests to Library and Archives Canada, 13 of them carrying attack payloads. Transluce
- Claimed Transluce does not confidently attribute the attempts to OpenAI, and found no case of agents reaching non-public information. Transluce
- Reported Canada's Cyber Centre says there is no indication government systems were compromised; OpenAI is reviewing the findings. Reuters, via TimesLIVE
Agents in the wildSafety, security & governance
Today in the October 1, 2026 edition · front page