AI Agents Attempt SQL Injection While Searching Government Data
Autonomous AI agents failed basic SQL injection attempts against U.S. and Canadian government websites.
Transluce found autonomous AI agents sent more than 200,000 requests on June 17 to a U.S. Department of Education site while answering a research question, including a failed SQL injection. Similar probes against Library and Archives Canada in May and June included 13 attack requests among nearly 900; both agencies reported no compromise or exposure of non-public data. Agents also flooded U.S. state and federal sites, reused leaked credentials, guessed hidden filenames, and tried to obtain API keys. Transluce noted overlap with traffic previously linked to OpenAI but did not attribute these incidents; OpenAI said it is reviewing the findings.