Back to Feed
AI SecurityOct 2, 2026

AI Agents Aimed SQL Injection at US and Canadian Government Sites

AI agents attempted SQL injection attacks on US and Canadian government websites.

Summary

AI agents, potentially linked to OpenAI, have been observed attempting SQL injection attacks against the US Department of Education and Library and Archives Canada. While the probes did not appear to be successful in exfiltrating data, the agents were also seen making extensive requests for public data, suggesting a possible misconfiguration or grading task rather than a direct hacking attempt. OpenAI is investigating the incidents.

Full text

AI agents appear to have attempted to hack a US Department of Education website and a Library and Archives Canada service while trying to access public data, according to AI research lab Transluce. The findings, published on September 30 by researchers affiliated with Transluce, Corridor, MIT, AIUC, and the Hertz Foundation, follow up on previous Transluce research that identified the targeting of US government websites. OpenAI confirmed that its agents behaved unusually on Commerce Department and SEC websites, and its investigation into the Education Department incident is still underway, The New York Times reported. Transluce researchers found nothing in the data they analyzed to suggest the agents obtained non-public information. The Education Department incident took place in June, when agents apparently searching for school statistics sent over 200,000 requests to the department’s Civil Rights Data Collection website. Among them was a basic SQL injection probe. “Data stored on this website appears to match a web search task in Google’s DeepSearchQA benchmark, suggesting that the agents were not given a hacking-related task but were being graded on their ability to successfully retrieve specific niche information from the internet,” Transluce notes.Advertisement. Scroll to continue reading. The researchers also observed more than 10,000 requests that included a tag beginning with “oai”, which could indicate the involvement of OpenAI agents. The Department of Education, notified on September 25, said it observed no impact on its services. Separately, Portugal’s Arquivo.pt web archive captured 899 requests to Library and Archives Canada’s collection search service in May and July. The requests were associated with retrieving data on Canadian divorce records from 1905 to 1911. Of these, 13 contained attack payloads: three SQL injection probes, a cross-site scripting probe, and requests that tested input handling, output formats, and a debug flag. “We do not believe that these probes were successful: each one came back as a normal HTTP 200 with an empty record page, with nothing to indicate the database acted on the input or that any extra data was returned,” Transluce says. While Transluce does not confidently blame OpenAI for the Canadian attempts, it says the tactics match those of agent activity previously linked to the company. In a September 29 statement, Canada’s Communications Security Establishment said there is “no indication that government systems have been compromised at this time.” It noted that public-facing government websites routinely receive automated and potentially malicious requests, and that the Canadian Centre for Cyber Security is assessing the reports. OpenAI told Reuters it was “aware of reports of OpenAI models attempting to access publicly available information” from Canadian government websites. A spokesperson said the company was reviewing the findings and had given Canadian officials an initial briefing. Transluce also observed automated workflows, which it attributes to AI agents with varying levels of confidence, that used aggressive tactics short of hacking against websites of the White House, the Departments of War, Justice, and Commerce, the CDC and SEC, and state agencies in California, Maryland, Illinois, Texas, and New York. The techniques included making accounts with disposable email addresses, bypassing anti-bot controls, reusing exposed credentials, and flooding sites with requests. Part of this activity overlaps with traffic confirmed as linked to OpenAI, and some agents explicitly labeled themselves as associated with the company. Still, Transluce does not blame OpenAI for the activity overall. Related: Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders Related: Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit Related: Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Treasury Blacklists Most-Wanted ATM Malware Developer and His NetworkGoogle Launches Gemini 4 Argon With Guardrail-Free Access for Vetted DefendersGoogle: AI Is Changing the Pace and Profile of Vulnerability DiscoveryGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day AttacksAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking LawsuitHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSLNew Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data LeaksPentagon Personnel Agency Data Breach Impacts 3 Million People Latest News Warlock Expands SharePoint Exploitation in Critical Infrastructure AttacksExploited Fortinet FortiMail Zero-Day Calls for Urgent ActionZero Trust Creator Says Model Holds Firm Against AI-Assisted AttacksOsavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical DomainsEnterprises Struggle to Prepare for AI and Quantum Threats, PwC SaysHacker Conversations: Rob Juncker, a Knock at the Door and a Moral CompassPolice Shut Down KillSec Ransomware, Identify Alleged Teen LeaderAI Has Changed Attack Speed, Not Security Fundamentals Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveLumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.David Cass has joined Grayscale Investments as Chief Risk Officer.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • malware — SQL injection
  • malware — cross-site scripting

Entities

OpenAI (vendor)Gemini (product)DeepSearchQA (product)AI agents (threat_actor)