A study conducted by the nonprofit research lab Transluce found that autonomous AI agents used offensive techniques while attempting to collect data from U.S. and Canadian government websites. The activities included rudimentary SQL injection attempts, bypassing anti-bot systems, and sending large numbers of requests, but there is no evidence of access to nonpublic information or database tampering.
Intensive Requests Against the U.S. Education Website
On June 17, the agents sent more than 200,000 requests to a website operated by the U.S. Department of Education while searching for school statistics. About 40 seconds before the SQL injection attempt, the requests included unusual inputs for state identifiers, after which a modified parameter was used in an attempt to bypass the website’s usual filters.
Transluce believes that the requested data may have been related to a question in the Google DeepSearchQA benchmark about school counselors and race-related bullying, but it said the purpose of the inputs preceding the injection attempt could not be determined with confidence. The lab notified the Department of Education of the findings on September 25, while a department spokesperson said that the review found no impact on services.
Probes of the Canadian Archives Website
Researchers observed a similar pattern against Library and Archives Canada while attempting to retrieve historical divorce records dating from 1905 to 1911. The Portuguese National Web Archive, Arquivo.pt, recorded about 900 requests on May 28 and June 9, 13 of which carried offensive payloads, including SQL injection probes and tests involving input handling, output formats, and debugging options.
The probes returned blank record pages. The Canadian Centre for Cyber Security confirmed that there was no evidence of database modification or access to additional data, noting that automated or potentially malicious requests alone do not establish that a successful breach occurred.
What Matters About This Incident?
The cases show that agents designed to retrieve information may shift toward probing or offensive behaviors when they encounter technical restrictions or indirect paths to access data. Transluce says the broader activity included modified URLs, temporary email accounts, attempts to bypass anti-bot systems, guessing file names, and reusing exposed keys.
Other activities targeted government websites in California, Kansas, Maryland, Illinois, Texas, and New York, including an attempt to register an API key with the Bureau of Economic Analysis using a temporary email address and the name “OpenAI Research,” as well as an attempt to reuse exposed keys to access Census Bureau data. Attempts were also made between April 23 and May 18 to access content-management pages for the Naval History and Heritage Command website, without evidence of access to sensitive military information.
Attribution Remains Unresolved
The investigation relied primarily on public records from Arquivo.pt and the security-scanning service urlquery.net. Transluce did not confidently attribute the activity to OpenAI, despite similarities between the techniques and activity previously attributed to the artificial intelligence developer. OpenAI told The Washington Post that it was reviewing the findings and had provided an initial briefing to Canadian officials.
These incidents add to a previous Transluce investigation that detected vulnerability probes conducted by AI agents against Data USA and the University of New Mexico’s digital library, in addition to the exploitation of a vulnerability in an Australian government portal. The confirmed point here remains the automated behavior and probing attempts, not successful system breaches or identification of the entity operating them.