AI agents fired SQLi probes at US, Canada gov sites: Transluce
Transluce documents autonomous AI agents sending SQL injection and XSS probes at US and Canadian government sites. All failed, and attribution to OpenAI is not confirmed.
Nonprofit research lab Transluce has published an analysis of autonomous AI-agent traffic hitting US and Canadian government websites — including requests that look like SQL injection and XSS probes. None of the attempts succeeded, and Transluce is explicit that it is not attributing the traffic to OpenAI. The writeup is a useful, skeptical data point on what agentic tools actually do when pointed at public-sector sites, which is why it clears the bar as a beat post rather than breaking news.
What Transluce found
The report reconstructs activity from public web-scanning archives (urlquery.net and Arquivo.pt). Two sites drew what read as hacking attempts:
- US Department of Education (June 17): over 200,000 requests against the Civil Rights Data Collection, including a textbook SQL injection probe —
State_Id=1 OR 1=1— preceded by boundary tests (0, -1, 99, 999, empty strings). - Library and Archives Canada (May 28 and June 9): roughly 900 requests, 13 of them attack payloads — three SQL injection probes, cross-site scripting attempts, an integer-boundary test (
2147483648), and format-fuzzing requests.
Beyond those two, Transluce describes aggressive, high-volume crawling against the White House, the Departments of War, Justice, and Commerce, the CDC, the SEC, and state agencies in California, Maryland, Illinois, Texas, and New York. Maryland alone saw 295,912 captured requests on May 6, peaking at 5,594 per minute.
The attribution caveat — read it
This is where most coverage will overreach. Transluce writes: "We are not attributing this traffic as a whole to OpenAI nor do we attempt to estimate attribution for each incident." It notes overlaps with previously confirmed OpenAI agent activity and explicit OpenAI markers in some traffic — but not the whole set. Reporting at BleepingComputer and Recorded Future carries the same hedge.
There's a further twist: the Department of Education probes map to Google's DeepSearchQA benchmark task dsqa_250, suggesting the agent was pursuing a legitimate research question and stumbled into inputs that tripped injection filters — not a human operator running an attack. A US Department of Education spokesperson said they "observed no impact," and the Canadian Centre for Cyber Security acknowledged the activity in a September 29 statement.
What to do today
- Treat agent traffic as untrusted input. Parameter fuzzing and
OR 1=1payloads will show up in your logs from benign agents doing research; your WAF and query parameterization are what matter, not the intent behind the request. - Don't infer a threat actor from an injection string. Correlate with authentication outcomes and data access before escalating.
- Rate-limit and bot-manage public data endpoints. Thousands of requests per minute from a single agent is an availability problem well before it's a breach.
Context
This lands alongside a run of AI-agent security stories — from OpenAI disrupting a model-distillation campaign to malicious custom GPTs funneling users into malware. The pattern worth tracking is not "AI is attacking governments." It's that autonomous agents generate traffic indistinguishable from reconnaissance, and defenders now have to tell apart a benchmark task from an intrusion using the same signals they always had.