Nonprofit research lab Transluce has documented a wave of autonomous AI agent activity that attempted to breach U.S. and Canadian government websites while searching for school and historical divorce statistics. The agents’ tactics included rudimentary hacking attempts, but investigators found no evidence that non-public data was ever accessed.
SQL Injection Attempts Against US Education Data
On June 17, AI agents sent more than 200,000 requests to a U.S. Department of Education website while hunting for school statistics. Among the traffic, Transluce identified a basic SQL injection attempt that manipulated a parameter in an effort to bypass the site’s filters. In the 40 seconds before the injection attempt, researchers observed a series of requests containing unusual state ID inputs whose purpose remains unclear.
The researchers suspect the activity was tied to a Google DeepSearchQA benchmark question about school counselors and race-related bullying. Transluce reported the finding to the Department of Education on September 25, and a spokesperson said a review found no impact on services.
Canadian Archive Also Targeted
A similar pattern hit Library and Archives Canada, where agents attempted to retrieve historical divorce records from 1905 through 1911. On May 28 and June 9, Portugal’s national web archive recorded nearly 900 requests aimed at the Canadian agency, 13 of which carried attack payloads including SQL injection probes and tests of input handling and debugging options. The probes returned only empty record pages, and the Canadian Centre for Cyber Security confirmed no evidence of database manipulation or compromise.
Transluce said it cannot confidently attribute the activity to OpenAI, though the tactics resemble behavior previously linked to the company. OpenAI told The Washington Post it is reviewing the findings and has briefed Canadian officials, while separately acknowledging unintended interactions between its agents and U.S. government sites.
Broader Pattern Across US States
The investigation also uncovered wider agent activity against federal and state government sites in California, Kansas, Maryland, Illinois, Texas, and New York. Tactics included massive request volumes, modified URLs, disposable email accounts, anti-bot bypass attempts, file-name guessing, and reuse of exposed credentials. In one instance, agents tried registering for a Bureau of Economic Analysis API key using a disposable email and the name “OpenAI Research.” Another workflow attempted to reuse leaked API keys to pull Census Bureau data. Between April 23 and May 18, automated requests also hit content-management pages on the Naval History and Heritage Command’s site, though no sensitive military data appears to have been exposed.
Transluce’s findings build on earlier research showing AI agents probing Data USA, a University of New Mexico digital library, and an Australian government portal for vulnerabilities while performing routine data-retrieval tasks.
