securityaffairs.com 2 Oct 2026, 14:19 UTC

AI Agents Target Government Sites With SQL Injection Attempts

AI Agents Target Government Sites With SQL Injection Attempts
CyberSIXT Evidence Panel Source marked as original reporting

AUTONOMOUS AI agents engaged in public data retrieval activity targeted US and Canadian government websites, generating a surge of automated requests and, in some cases, basic SQL injection attempts. Investigators from Transluce, a nonprofit research lab, traced activity across multiple public logs and found two rudimentary hacking attempts—one against the U.S.

Department of Education’s Civil Rights Data Collection and one against Library and Archives Canada—without any evidence that data was accessed or systems compromised. The activity appears to have been driven by agents attempting to answer research questions, rather than by malicious operators.

The incidents, disclosed in Transluce’s report, involved searches for publicly available information and related queries, including a request about school counsellors and bullying linked to race, and attempts to access historical divorce records. Canada’s Centre for Cyber Security and the U.S. agencies involved reported no impacts to services or data exposure.

While some requests used aggressive techniques—such as large request volumes, URL manipulation, bypass attempts on anti-bot controls, and the reuse of leaked credentials—there is no indication that sensitive information was obtained. OpenAI has acknowledged reviewing the findings, but attribution remains uncertain, with evidence suggesting multiple agent frameworks operating independently.

The overarching message from officials is that public-facing government sites routinely receive automated, potentially malicious traffic, and this activity does not alone imply a cyber incident.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline