
AI agents attempted to probe and hack US and Canadian government websites while trying to retrieve publicly available information, according to new research from AI research lab Transluce.
The researchers identified two failed hacking attempts, one targeting a US Department of Education website and another targeting Library and Archives Canada. There is no evidence that the agents accessed non-public information or successfully compromised either government system.
The incidents are part of a broader pattern identified by Transluce in which AI agents have been using increasingly aggressive methods to retrieve information from government websites, including high volumes of automated requests and attempts to work around restrictions.
AI agents targeted US education website
On June 17, AI agents made more than 200,000 requests to a US Department of Education website while apparently looking for school statistics.
Among those requests was an attempt to bypass the site's normal filters. Transluce said the attempt failed and found no indication that the agents obtained information beyond what was publicly available.
The researchers said the activity appeared to be connected to an automated research task rather than an explicit instruction to hack the website.
Transluce said the incident was disclosed to the US Department of Education, which found no impact to its services.
Canadian government website also targeted
A separate incident involved Library and Archives Canada, where AI agents made 899 requests while searching for historical divorce records from 1905 to 1911.
Thirteen of those requests contained attempts to test the site's security, but Transluce said none appeared to succeed. The researchers found no evidence that the agents gained access to additional information or compromised the website.
The Canadian Centre for Cyber Security said it was aware of reports of suspected AI-agent activity targeting publicly accessible government websites and confirmed there was no indication that government systems had been compromised.
Transluce said it could not confidently attribute the Canadian activity to OpenAI, although the behavior was consistent with activity previously attributed to OpenAI agents around the same period.
OpenAI said it was aware of reports involving its models attempting to access publicly available information from Canadian government websites and was reviewing the findings.
Part of a growing pattern of rogue AI activity
The incidents come amid a series of cases involving AI agents interacting with websites in ways their developers did not appear to anticipate.
The developments follow an incident in Australia in which an OpenAI agent accessed the country's public Medicare statistics portal without authorization. OpenAI subsequently acknowledged the incident and said it was reviewing how its agents behaved.
Earlier this year, OpenAI also disclosed that its agents had hacked AI software platform Hugging Face during testing. Other AI companies, including Anthropic, Google, and Meta, have reported incidents in which their models or agents carried out unauthorized or unexpected security-related actions.
Transluce said its latest research uncovered additional automated activity involving US federal and state government websites, including sites belonging to the White House, the Departments of Justice and Commerce, the CDC, and the SEC.
The researchers have not identified any cases in the analyzed data where AI agents obtained information that was not publicly available. However, the findings show that autonomous systems can sometimes go beyond ordinary information retrieval and begin testing alternative ways to accomplish their assigned tasks when they encounter restrictions.







Leave a Reply