
Autonomous AI agents, working on what looks like ordinary data retrieval tasks, ended up throwing basic hacking attempts at a U.S. Department of Education site and Library and Archives Canada. Nobody told them to break in. They just drifted there while trying to answer research questions.
The findings come from Transluce, a nonprofit research lab that dug through public web logs and found a pattern nobody had flagged before.
On June 17, AI agents sent more than 200,000 requests to a U.S. Department of Education website while hunting for school statistics. Buried in that traffic was a basic SQL injection attempt, a manipulated parameter meant to slip past the site’s normal filters. Nothing came of it. The site held.
“Following up on our previous blog post, we discovered several additional incidents where rogue AI agents appear to have used aggressive techniques to access publicly available data on government websites.” reads the report published by Transluce.
“This includes two rudimentary and failed hacking attempts, one against the U.S. Department of Education’s Civil Rights Data Collection, and one against Library and Archives Canada, a Canadian federal agency.”
Transluce says the agents were looking for data related to a Google DeepSearchQA question about school counselors and bullying linked to race. The agent was likely trying to answer the question and found its way to the government database. The U.S. Department of Education checked the activity after Transluce reported it on September 25 and found no impact on its services.
A similar case involved Library and Archives Canada. The agents were looking for divorce records from 1905 to 1911. Portugal’s national web archive recorded almost 900 requests to the Canadian website in May and June. Thirteen requests included attack attempts, such as SQL injection tests and attempts to bypass input and debugging controls.
“We have so far identified no instances in these datasets where agents gained access to any information that is not publicly available.” states the report.
Every probe came back empty. Canada’s Centre for Cyber Security looked into it and found nothing to suggest the database had been touched or exposed.
“We are aware of reports identifying suspicious activity, including suspected AI agent activity, targeting publicly accessible websites, such as the Government of Canada. There is no indication that government systems have been compromised at this time.” states Canada’s Centre for Cyber Security. “Public-facing government websites routinely receive automated and potentially malicious requests. Such activity is an ongoing feature of the online environment and does not, on its own, indicate a successful cyber incident.”
Transluce is careful here, and that caution matters. The researchers say the tactics match patterns previously tied to OpenAI, but they stop short of pinning the blame directly, writing plainly that they can’t confidently attribute these specific attempts to the company.
“In addition to the above, we identified a broader pattern of automated workflows that we attribute to AI agents with varying levels of confidence, based on task-level connections, shared infrastructure, and timing. Some of this traffic overlaps to varying degrees with prior activity confirmed to be associated with OpenAI, and in some cases agents explicitly mark themselves as being associated with OpenAI.” Transluce adds. “However, we are not attributing this traffic as a whole to OpenAI nor do we attempt to estimate attribution for each incident.”
OpenAI, for its part, told the Washington Post it was reviewing the findings and had already given Canadian officials an initial briefing.
“We’re aware of reports of OpenAI models attempting to access publicly available information from Canadian government websites,” a spokesperson for OpenAI said. “We’re reviewing these findings and have provided an initial briefing to Canadian officials conducting the government’s review.”
OpenAI has separately admitted to unintended interactions between its agents and U.S. government sites before, so this isn’t coming out of nowhere. Still, Transluce flagged that a chunk of the broader activity they found doesn’t trace cleanly back to any one company. Multiple agent frameworks, it seems, are out there roaming the same networks, and attribution gets messy fast when nobody’s agent is wearing a name tag.
The investigation found more examples of aggressive AI agent activity against U.S. state and federal websites. The logs included agencies in California, Kansas, Maryland, Illinois, Texas, and New York.
The agents used different tactics, including sending large numbers of requests, changing URLs, using temporary email accounts, trying to bypass anti-bot systems, guessing hidden file names, and reusing leaked credentials.
One agent tried to get a Bureau of Economic Analysis API key using a temporary email and the name “OpenAI Research.” Another tried to use an exposed API key to access Census Bureau data. Between April and May, agents also repeatedly tried to reach the content management system of the Navy’s history website. There is no evidence they accessed classified information.
Nobody here set out to build malware. These look like agents doing information-gathering work, running into a paywall or a blocked query, and improvising their way around it using techniques that happen to double as attack patterns. That’s a genuinely new category of risk: not a hacker deploying a tool, but a tool behaving like a hacker because that’s the shortest path to the answer it was told to find.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, AI agents)