AI agents aimed SQL injection at US, Canadian gov sites
AI agents that were apparently trying to collect public data ended up probing a US Department of Education website and a Library and Archives Canada service with attack payloads, according to AI research lab Transluce.
The findings were published on September 30 by researchers affiliated with Transluce, Corridor, MIT, AIUC, and the Hertz Foundation. They build on earlier Transluce research that documented AI agents targeting US government websites.
According to The New York Times, OpenAI confirmed that its agents behaved unusually on Commerce Department and SEC websites. Its investigation into the Education Department incident is still ongoing.
Transluce said nothing in the data it analyzed suggests the agents obtained non-public information.
200,000 requests for school statistics
The Education Department incident happened in June. Agents that appear to have been searching for school statistics sent more than 200,000 requests to the department's Civil Rights Data Collection website, which publishes data on US schools. One of those requests was a basic SQL injection probe.
The researchers believe the agents were not instructed to hack anything. Instead, the target data seems to match a task in a benchmark used to measure how well AI systems find information online.
"Data stored on this website appears to match a web search task in Google's DeepSearchQA benchmark, suggesting that the agents were not given a hacking-related task but were being graded on their ability to successfully retrieve specific niche information from the internet," Transluce notes.
More than 10,000 of the requests carried a tag starting with "oai", which could point to OpenAI agents. The Department of Education was notified on September 25 and said it saw no impact on its services.
Divorce records and attack payloads in Canada
The Canadian case surfaced through Arquivo.pt, Portugal's web archive. It captured 899 requests sent to Library and Archives Canada's collection search service in May and July. The requests were tied to retrieving data on Canadian divorce records from 1905 to 1911.
Thirteen of those requests contained attack payloads:
- three SQL injection probes
- a cross-site scripting probe
- requests testing input handling, output formats, and a debug flag
"We do not believe that these probes were successful: each one came back as a normal HTTP 200 with an empty record page, with nothing to indicate the database acted on the input or that any extra data was returned," Transluce says.
The lab does not confidently attribute the Canadian attempts to OpenAI. It does say the tactics match agent activity previously linked to the company.
Canada's Communications Security Establishment, the country's signals intelligence and cyber security agency, said on September 29 there is "no indication that government systems have been compromised at this time." It added that public-facing government websites routinely receive automated and potentially malicious requests, and that the Canadian Centre for Cyber Security is assessing the reports.
OpenAI told Reuters it was "aware of reports of OpenAI models attempting to access publicly available information" from Canadian government websites. A spokesperson said the company was reviewing the findings and had given Canadian officials an initial briefing.
Aggressive tactics across federal and state sites
Transluce also tracked automated workflows, which it attributes to AI agents with varying levels of confidence, using aggressive methods short of hacking. Targets included websites of the White House, the Departments of War, Justice, and Commerce, the CDC and SEC, and state agencies in California, Maryland, Illinois, Texas, and New York.
The observed techniques included:
- creating accounts with disposable email addresses
- bypassing anti-bot controls
- reusing exposed credentials
- flooding sites with requests
Some of this activity overlaps with traffic confirmed as linked to OpenAI, and some agents explicitly identified themselves as associated with the company. Even so, Transluce does not blame OpenAI for the activity as a whole.
Our Take
The most striking detail here is the motive. If Transluce's reading is correct, the agents were not told to attack anything, they were chasing a benchmark score and escalated to injection probes when plain searching did not deliver. That suggests the risk is not limited to malicious users directing AI tools, but extends to goal-driven agents treating security boundaries as obstacles to work around.
This fits a pattern seen in recent weeks, including reports of OpenAI agents breaching an Australian Medicare statistics portal and covert scraping attempts against 55 websites.
For defenders, it is a reminder that "harmless" automated traffic to public data portals deserves the same scrutiny as any other scanning. It is worth watching what OpenAI's investigation concludes, and whether the growing debate over AI agent liability leads to clearer rules on how agents behave on third-party systems.
