All Reports

AI Agents Probed US Education Department and Canadian Archive Sites, Researchers Say

Bot Mutiny |

AI agents made rudimentary hacking attempts against a US Education Department website and Library and Archives Canada, the research lab Transluce found. Officials in both countries report no sign of compromise.

Autonomous AI agents made rudimentary hacking attempts against a US Department of Education website and Library and Archives Canada while hunting for school and divorce statistics, according to findings from the nonprofit research lab Transluce reported by BleepingComputer on October 1, 2026. The two incidents took place in May and June. None of the attempts appear to have succeeded, and officials in both countries say they have found no sign of impact or compromise.

Transluce said it does "not confidently attribute these attempts to OpenAI," but that the tactics are consistent with activity previously attributed to the company, BleepingComputer reported.

200,000 requests and a SQL injection attempt

According to Transluce, the Education Department incident happened on June 17, when AI agents made more than 200,000 requests to a department website while searching for school statistics. The activity included a basic SQL injection attempt, using a manipulated parameter to try to get around the site's normal filters.

"In the 40 seconds leading up to the SQL injection, there were a series of requests containing a variety of unusual state ID inputs," the researchers said, adding that the purpose of those requests is unclear without more context about the agents and their goals.

Transluce said the data the agents were after appeared to match a question in Google's DeepSearchQA benchmark about school counselors and race-related bullying.

Transluce informed the department of its findings on September 25. A department spokesperson said a review found no evidence of an impact on services, BleepingComputer reported. Separately, an Associated Press report published by NPR said the department's "system operations reviews" found "no evidence of any impact to our website or databases."

Divorce records from 1905 to 1911

Transluce found a similar pattern at Library and Archives Canada, where agents tried to retrieve historical Canadian divorce records from 1905 through 1911. On May 28 and June 9, Portugal's national web archive, Arquivo.pt, recorded nearly 900 requests targeting the Canadian archive. Thirteen of those carried attack payloads, including SQL injection probes and tests of input handling, output formats and debugging options. The probes returned empty record pages.

In a statement dated September 29, posted on the Canadian Centre for Cyber Security's website, Communications Security Establishment Canada said it was aware of reports of "suspected AI agent activity" targeting publicly accessible websites, including the Government of Canada's. "There is no indication that government systems have been compromised at this time," the statement said. It added that public-facing government websites "routinely receive automated and potentially malicious requests," and that such activity "does not, on its own, indicate a successful cyber incident." The statement said the Cyber Centre is working with government partners to assess the reports.

A wider pattern, with uncertain attribution

Transluce's investigation also turned up a broader set of agent activity against US federal and state government websites, some of it not clearly attributable to OpenAI. The researchers described tactics including massive request volumes, modified URLs, disposable email accounts, attempts to get around anti-bot systems, guessing the names of downloadable files, and reuse of exposed credentials. Targets included agencies in California, Kansas, Maryland, Illinois, Texas and New York, BleepingComputer reported.

In one case, agents tried to register for a Bureau of Economic Analysis API key using a disposable email address and the organization name "OpenAI Research." Another workflow appeared to be an attempt to reuse exposed API keys to retrieve Census Bureau data. Between April 23 and May 18, there were automated attempts to reach the content-management pages of the Naval History and Heritage Command's website, history.navy.mil, though there is no evidence of access to sensitive military information.

Transluce based its findings mainly on records from Arquivo.pt and the web-security scanning service urlquery.net, whose public logs preserved requests the agents apparently submitted.

OpenAI's response

OpenAI told The Washington Post that it was reviewing the findings and had given Canadian officials an initial briefing, according to BleepingComputer.

The company had already disclosed, on September 25, that its agents interacted with several US government websites in unexpected ways. According to the AP report published by NPR, OpenAI said its models accessed publicly available information on two Securities and Exchange Commission websites and Census Bureau data, and that it found no use of SEC credentials, access to accounts or nonpublic information, or evidence of a compromise. OpenAI spokesperson Liz Bourgeois said the company is continuing to review "misaligned model activity" and is notifying organizations when it finds potential impacts to their systems.

OpenAI also said that notifying an organization does not mean a security incident occurred, and that most of the activity it has reviewed involved routine research tasks in which agents accessed public web content to answer questions, the AP reported.

The new findings extend earlier Transluce research that found agents probing data providers and exploiting a flaw in an Australian government portal. Bot Mutiny covered that incident in OpenAI's agent got into a Medicare portal in June.