Rogue AI agents targeted US and Canadian government websites with aggressive probes and failed hacking attempts while trying to access publicly available data.
Artificial intelligence (AI) agents have been observed using aggressive techniques to probe US and Canadian government websites, including two failed hacking attempts targeting the US Department of Education and Library and Archives Canada, according to new findings from AI research firm Transluce.
The incidents were uncovered through publicly available data from urlquery.net and Arquivo.pt, a Portuguese web archive. Transluce said it found no evidence that the AI agents accessed information that was not already publicly available.
AI Agents Probe Education DepartmentOne of the most notable incidents occurred on June 17, when AI agents made more than 200,000 requests to a Department of Education website while apparently searching for school statistics.
Transluce said the activity included a rudimentary SQL injection attempt, with agents inserting "State_Id=1 OR 1=1" into a request in an apparent effort to bypass the site's normal filtering. Researchers said the activity appeared connected to a Google DeepSearchQA benchmark task that asked agents to compare school counselor and student harassment data across several states.
More than 10,000 requests also contained a tag beginning with "oai." Transluce said 99.6% of those requests used the same combination of query parameters associated with the benchmark task.
"We disclosed this attempted hack to the Department of Education on September 25, 2026. A Department spokesperson subsequently commented that they had observed no impact to their services from this reported incident," the researchers added.
Freepik
A second series of activity involved Library and Archives Canada. Arquivo.pt captured 899 requests on May 28 and June 9 directed at the agency's "collection-search" service.
The requests were associated with attempts to retrieve Canadian divorce records from 1905 to 1911. Among them, 13 carried what Transluce described as attack payloads targeting vulnerabilities in a record-identifier parameter.
Researchers said they did not believe the attempts succeeded. Each request returned a normal HTTP 200 response with an empty record page, with no indication that the database processed the malicious input or returned additional information.
Transluce said it could not confidently attribute those attempts to OpenAI, although some tactics resembled activity it had previously linked to the company.
Broader Pattern Across Government WebsitesWe do not believe that these probes were successful: each one came back as a normal HTTP 200 with an empty record page, with nothing to indicate the database acted on the input or that any extra data was returned.
We disclosed this attempted hack to the Canadian government on September 28, 2026. On September 29, the Canadian Centre for Cyber Security issued a public statement in response.
Beyond the two failed hacking attempts, Transluce identified a wider pattern of AI-driven workflows using aggressive or "gray-area" methods to collect publicly available information.
The activity involved government websites connected to Kansas, Illinois, Maryland, New York, Texas and California, as well as the White House Office of Management and Budget, the US Navy, Justice Department, Bureau of Economic Analysis, Census Bureau, Securities and Exchange Commission and Centers for Disease Control and Prevention. Researchers said these workflows sometimes used disposable email addresses, exposed credentials, anti-bot bypasses or large volumes of requests.
Transluce emphasized that it was not attributing the entire collection of activity to OpenAI. Researchers said attribution varied in confidence and was based on factors including task-level connections, infrastructure and timing.
The findings arrive amid growing concern over autonomous AI systems interacting with real-world digital infrastructure. Transluce said its analysis relied on automated traffic patterns, exploit indicators and human investigation to distinguish likely agent activity from ordinary web requests.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Неизвестные ИИ-агенты атаковали сайт правительства Канады | 0 | 26.67 | 01-10-2026 |
| 2 | ИИ-агенты атаковали сайты правительства Канады | 0 | 14.93 | 01-10-2026 |
| 3 | WP: неизвестные агенты ИИ пытались взломать сайты правительства Канады | 0 | 6.69 | 01-10-2026 |
| 4 | СМИ: неизвестные агенты ИИ пытались взломать сайты правительства Канады | 0 | 10.95 | 01-10-2026 |
| 5 | Nuevo incidente con la IA de Open AI: intenta acceder sin permiso a webs del Gobierno de Estados Unidos | 0 | 6.94 | 26-09-2026 |
| 6 | OpenAI hack sparks further concern over AI models going rogue | 0 | 7.01 | 28-09-2026 |
| 7 | Rogue AI bots have hacked into governments, universities and public agencies around the world, tech giant OpenAI admits | 0 | 7.19 | 26-09-2026 |
| 8 | Нулевой закон: почему ИИ-модели выходят из-под контроля | 0 | 20.51 | 01-10-2026 |
| 9 | OpenAI Agent Breached Australia’s Medicare Data Portal, Government Says | 0 | 5.62 | 24-09-2026 |
| 10 | OpenAI says its models engaged with US government websites in misbehavior disclosure | 0 | 5.92 | 26-09-2026 |