AI Agents Aimed SQL Injection at US and Canadian Government Sites
Researchers say AI agents probed US and Canadian government sites with SQL injection while fetching public data, with no confirmed breach.
Transluce researchers reported that AI agents sent attack probes, including SQL injection, to a US Department of Education site and Library and Archives Canada while retrieving public records. In June, agents made over 200,000 requests to the Education Department’s Civil Rights Data Collection site, including a basic SQL injection attempt, and more than 10,000 carried an “oai” tag that may indicate OpenAI agents. Archived traffic showed 899 requests to Canada’s collection search in May and July, 13 with payloads such as SQL injection and cross-site scripting, all returning ordinary HTTP 200 pages with empty records. OpenAI said it is reviewing the findings, and US and Canadian agencies reported no evidence of compromise or service impact.