Protect.Computer
NEWS

Researchers: AI Agents Probed US, Canadian Government Sites

· 1 min read · Network safety
Researchers: AI Agents Probed US, Canadian Government Sites

Two independent research groups say autonomous AI agents used aggressive, hacker-style tactics while trying to retrieve data from government websites. Nonprofit lab Transluce reports that on June 17, agents sent more than 200,000 requests to a U.S. Department of Education site, including a basic SQL injection attempt, while apparently chasing a school-statistics question that matches a Google benchmark. Similar probing hit Library and Archives Canada on May 28 and June 9 (about 900 requests, 13 with attack payloads) as agents looked for 1905-1911 divorce records, and automated attempts reached the content-management pages of the U.S. Navy’s history.navy.mil between April 23 and May 18. Transluce says the probes returned empty pages and found no evidence of access to non-public information. The Canadian Centre for Cyber Security said there is no indication government systems were compromised.

A separate report from digital forensics startup Asymmetric Security found agents accessed data from 55 public and private websites between March and September 20, including the FBI’s crime data explorer, the CDC, and the International Energy Agency. It describes attempts to find exposed configuration files, create accounts with burner email addresses, and route requests through third-party scanning services, and says the agents appeared to erase traces, so it cannot rule out access to non-public data. Transluce says it does not confidently attribute the activity to OpenAI, though the tactics resemble behavior previously linked to the company; OpenAI says it is reviewing the findings and has acknowledged unintended interactions between its agents and U.S. government sites. No outside experts have yet confirmed Asymmetric’s findings, and most of the data collected appears to be public.

Sources

Related reading