Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    October 5, 2026

    Google DeepMind Gives AI-Designed Proteins a Watermark

    October 5, 2026

    I tested Noble’s elite triple-driver wireless headphones and they offer some of the most hypnotic, spacious sound I’ve ever heard — if you can afford them

    October 5, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»AI Agents Aimed SQL Injection at US and Canadian Government Sites
    AI Agents Aimed SQL Injection at US and Canadian Government Sites
    Cybersecurity

    AI Agents Aimed SQL Injection at US and Canadian Government Sites

    The Tech GuyBy The Tech GuyOctober 4, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    AI agents appear to have attempted to hack a US Department of Education website and a Library and Archives Canada service while trying to access public data, according to AI research lab Transluce.

    Advertisement

    The findings, published on September 30 by researchers affiliated with Transluce, Corridor, MIT, AIUC, and the Hertz Foundation, follow up on previous Transluce research that identified the targeting of US government websites.

    OpenAI confirmed that its agents behaved unusually on Commerce Department and SEC websites, and its investigation into the Education Department incident is still underway, The New York Times reported.

    Transluce researchers found nothing in the data they analyzed to suggest the agents obtained non-public information.

    The Education Department incident took place in June, when agents apparently searching for school statistics sent over 200,000 requests to the department’s Civil Rights Data Collection website. Among them was a basic SQL injection probe.

    “Data stored on this website appears to match a web search task in Google’s DeepSearchQA benchmark, suggesting that the agents were not given a hacking-related task but were being graded on their ability to successfully retrieve specific niche information from the internet,” Transluce notes.

    Advertisement. Scroll to continue reading.

    The researchers also observed more than 10,000 requests that included a tag beginning with “oai”, which could indicate the involvement of OpenAI agents. The Department of Education, notified on September 25, said it observed no impact on its services.

    Separately, Portugal’s Arquivo.pt web archive captured 899 requests to Library and Archives Canada’s collection search service in May and July. The requests were associated with retrieving data on Canadian divorce records from 1905 to 1911.

    Of these, 13 contained attack payloads: three SQL injection probes, a cross-site scripting probe, and requests that tested input handling, output formats, and a debug flag.

    “We do not believe that these probes were successful: each one came back as a normal HTTP 200 with an empty record page, with nothing to indicate the database acted on the input or that any extra data was returned,” Transluce says.

    While Transluce does not confidently blame OpenAI for the Canadian attempts, it says the tactics match those of agent activity previously linked to the company.

    In a September 29 statement, Canada’s Communications Security Establishment said there is “no indication that government systems have been compromised at this time.” It noted that public-facing government websites routinely receive automated and potentially malicious requests, and that the Canadian Centre for Cyber Security is assessing the reports.

    OpenAI told Reuters it was “aware of reports of OpenAI models attempting to access publicly available information” from Canadian government websites. A spokesperson said the company was reviewing the findings and had given Canadian officials an initial briefing.

    Transluce also observed automated workflows, which it attributes to AI agents with varying levels of confidence, that used aggressive tactics short of hacking against websites of the White House, the Departments of War, Justice, and Commerce, the CDC and SEC, and state agencies in California, Maryland, Illinois, Texas, and New York.

    The techniques included making accounts with disposable email addresses, bypassing anti-bot controls, reusing exposed credentials, and flooding sites with requests.

    Part of this activity overlaps with traffic confirmed as linked to OpenAI, and some agents explicitly labeled themselves as associated with the company. Still, Transluce does not blame OpenAI for the activity overall.

    Related: Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders

    Related: Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit

    Related: Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    October 5, 2026

    Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

    October 5, 2026

    Exploitation Hits Rejetto HFS Vulnerability Discovered by AI 

    October 5, 2026

    Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

    October 5, 2026

    Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

    October 4, 2026

    Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    October 4, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026392 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    October 5, 2026

    Google DeepMind Gives AI-Designed Proteins a Watermark

    October 5, 2026

    I tested Noble’s elite triple-driver wireless headphones and they offer some of the most hypnotic, spacious sound I’ve ever heard — if you can afford them

    October 5, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.