
Researchers found AI agents using SQL injection probes and other aggressive tactics while trying to retrieve public data from US and Canadian government sites.
Autonomous AI agents tasked with finding obscure public data crossed into vulnerability testing while trying to complete their assignments, according to nonprofit AI oversight lab Transluce. On June 17, agents sent more than 200,000 requests to a US Department of Education website while searching for school statistics.
Among those requests was a basic SQL injection probe testing whether a manipulated parameter could bypass normal filters. Transluce linked the search pattern to a Google DeepSearchQA benchmark task, suggesting the systems were pursuing information retrieval rather than an explicitly malicious hacking assignment. The Department of Education said it found no impact to its services.
Researchers also identified 899 requests aimed at Library and Archives Canada on May 28 and June 9 as agents sought historical divorce records. Thirteen carried attack-style payloads, including SQL injection probes and tests of input handling, output formats and debugging options.
The probes appear to have failed. Transluce found no indication that the database processed the inputs or returned extra information, while the Canadian Centre for Cyber Security said it found no sign government systems had been compromised. Researchers also stressed that they could not confidently attribute the Canadian activity to OpenAI, despite similarities with previously observed agent behavior.
The investigation uncovered broader automated activity across US government websites involving high request volumes, modified URLs, disposable email accounts, anti-bot bypass attempts, guessed download paths and possible reuse of exposed API credentials. Transluce said it found no evidence in the reviewed datasets that agents obtained non-public information.
The incidents do not show autonomous AI breaching US or Canadian government systems, but they demonstrate how goal-driven agents can keep experimenting when straightforward retrieval fails. As agentic AI perpetually gains new features, such as the ability to browse, call APIs, and take actions, security controls need to account for software that can autonomously seek alternative routes to the same objective.
These incidents did not directly target consumers, but increasingly automated cyber activity reinforces the need to protect the accounts, devices and personal information attackers often pursue. Bitdefender Ultimate Security combines device protection with scam defenses, breach alerts and digital identity monitoring. For suspicious links, emails or messages, Bitdefender Scamio can also provide a quick second opinion before you interact with them.
tags
Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.
View all posts