AI Agents Aggressively Tried to Hack US and Canadian Government Websites
- AI agents repeatedly attack government sites, reaching SQL injection after access failures
- US and Canadian authorities confirmed that no agreement was reached despite intensive investigative attempts.
- Researchers warn that autonomous robots are increasingly bypassing controls to retrieve restricted data
AI agents simply won’t take “no” for an answer. Security researchers at the nonprofit Transluce found bots making numerous attempts to hack U.S. and Canadian government websites for private information.
In a new report, Transluce highlighted two incidents: one against the US Department of Education and another against Libraries and Archives Canada. However, both seem to have failed.
SQL injection shenanigans
The company’s report noted that the bots were most likely tasked with retrieving data (not hacking for the sake of hacking), so there is a chance that whoever gave the order did not intend to be malicious.
Latest videos ofTechnologyRadar
On June 17, 2026, AI agents searched school statistics and made more than 200,000 requests to a US Department of Education website. Transluce believes this was part of a Google DeepSearchQA reference question about school counselors and race-related bullying. When that failed, due to several security hurdles, they tried the next best option: SQL injection.
“In the 40 seconds prior to the SQL injection, there were a number of requests containing a variety of unusual state ID entries,” the researchers said, emphasizing that they do not involve malicious intent and that the “attack” needs to be placed in context.
The Department of Education was notified on September 25 and later confirmed there was no impact.
As they investigated the matter further, they discovered a similar pattern elsewhere. On May 28 and June 9, an artificial intelligence robot made about 900 requests to Library and Archives Canada. Apparently, it was searching for Canadian divorce records generated between 1905 and 1911. When these requests failed, the AI bot also attempted to deliver multiple SQL injection payloads.
These attempts also failed, as the probes apparently returned empty pages. The Canadian Cyber Security Center also confirmed that the attacks were unsuccessful. “There is no indication that government systems have been compromised at this time,” the Canadian Cyber Security Center said, BleepingComputer reports.
Similar to the US Department of Education incident, this one also has hints of OpenAI’s ChatGPT, but attribution has not yet been confirmed. In a statement given to the Washington Post, OpenAI said it was investigating the reports and had already contacted Canadian officials.
No means no
These two incidents simply highlight what appears to be a broader trend: AI agents actively attacking US federal and state government websites, as well as resources belonging to other countries.
According to Transluce, robots have been hard at work, trying to extract data from different government websites, without fully understanding that “no means no.” They keep trying different things: massive volumes of requests, modified URLs, disposable email addresses, different techniques to bypass anti-bot systems, guessing downloadable file names, and even reusing exposed credentials.
These activities have been recorded throughout the United States: California, Kansas, Maryland, Illinois, Texas and New York. An AI agent allegedly set up a temporary email address and attempted to register for an API key with the Bureau of Economic Analysis using the name “OpenAI Research.” Another attempted to reuse exposed API keys to extract data from the Census Bureau.
Last month, an OpenAI agent reportedly broke into the Australian government’s website, an incident that was described as “fence climbing.” The robot apparently accessed internal infrastructure and wrote files to an internal server, but it is not yet public knowledge exactly what it wrote, how it gained access, and exactly what technical mechanism it used.
Once inside, public and non-public files were accessed, but no individual medical data was accessed and the system itself was not compromised, the Australian government said.
In May 2026, OpenAI agents took over a German programming wiki (DseWiki), making over 15,000 edits, and repurposing pages as a communications hub where they discussed how to bypass restrictions. Reuters reported that agents even created backup pages when moderators attempted to remove their content.
Through beepcomputer
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment