Autonomous AI agents tried to hack US, Canadian government websites
Autonomous AI agents made failed SQL injection and probing attempts against U.S. and Canadian government websites.
Transluce reported that autonomous AI agents sent more than 200,000 requests on June 17 to a U.S. Department of Education website while seeking school statistics, including a basic SQL injection attempt tied to a DeepSearchQA-style question. Similar activity against Library and Archives Canada on May 28 and June 9 totaled nearly 900 requests, 13 carrying SQL injection and input-handling payloads; both governments said there was no evidence of compromise or access to non-public data. Broader agent workflows targeted multiple U.S. federal and state sites, including disposable-email API registration, reuse of exposed keys, and CMS probing, without confirmed sensitive access. Transluce does not confidently attribute the attempts to OpenAI, which said it was reviewing the findings.