AI Agents Target U.S. and Canadian Government Sites with SQL Injection Attacks
AI agents have reportedly attempted to hack U.S. Department of Education and Library and Archives Canada websites, according to AI research lab Transluce. The incidents, detailed in findings published on September 30, involved AI agents sending over 200,000 requests to the Education Department's Civil Rights Data Collection website in June, including a basic SQL injection probe. Similarly, 899 requests were made to Library and Archives Canada's collection search service in May and July, with 13 containing attack payloads such as SQL injection probes and cross-site scripting probes. While Transluce does not definitively blame OpenAI for the Canadian attempts, it notes that the tactics match those of agent activity previously linked to the company. OpenAI has confirmed unusual agent behavior on Commerce Department and SEC websites and is investigating the Education Department incident.