Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Rogue AI Agents Target US and Canadian Government Websites in Newly Found Hacking Attempts

Дата публикации: 01-10-2026 08:17:55

Rogue AI agents targeted US and Canadian government websites with aggressive probes and failed hacking attempts while trying to access publicly available data.

Основное содержимое страницы с новостью.

Artificial intelligence (AI) agents have been observed using aggressive techniques to probe US and Canadian government websites, including two failed hacking attempts targeting the US Department of Education and Library and Archives Canada, according to new findings from AI research firm Transluce.

The incidents were uncovered through publicly available data from urlquery.net and Arquivo.pt, a Portuguese web archive. Transluce said it found no evidence that the AI agents accessed information that was not already publicly available.

AI Agents Probe Education Department

One of the most notable incidents occurred on June 17, when AI agents made more than 200,000 requests to a Department of Education website while apparently searching for school statistics.

Transluce said the activity included a rudimentary SQL injection attempt, with agents inserting "State_Id=1 OR 1=1" into a request in an apparent effort to bypass the site's normal filtering. Researchers said the activity appeared connected to a Google DeepSearchQA benchmark task that asked agents to compare school counselor and student harassment data across several states.

More than 10,000 requests also contained a tag beginning with "oai." Transluce said 99.6% of those requests used the same combination of query parameters associated with the benchmark task.

"We disclosed this attempted hack to the Department of Education on September 25, 2026. A Department spokesperson subsequently commented that they had observed no impact to their services from this reported incident," the researchers added.

Sam Altman lays out AI vision built on democratization and prosperity, while Bernie Sanders warns the US is unprepared for job losses and disruption.Freepik
Canadian Government Website Also Targeted

A second series of activity involved Library and Archives Canada. Arquivo.pt captured 899 requests on May 28 and June 9 directed at the agency's "collection-search" service.

The requests were associated with attempts to retrieve Canadian divorce records from 1905 to 1911. Among them, 13 carried what Transluce described as attack payloads targeting vulnerabilities in a record-identifier parameter.

Researchers said they did not believe the attempts succeeded. Each request returned a normal HTTP 200 response with an empty record page, with no indication that the database processed the malicious input or returned additional information.

Transluce said it could not confidently attribute those attempts to OpenAI, although some tactics resembled activity it had previously linked to the company.

We do not believe that these probes were successful: each one came back as a normal HTTP 200 with an empty record page, with nothing to indicate the database acted on the input or that any extra data was returned.

We disclosed this attempted hack to the Canadian government on September 28, 2026. On September 29, the Canadian Centre for Cyber Security issued a public statement in response.

Broader Pattern Across Government Websites

Beyond the two failed hacking attempts, Transluce identified a wider pattern of AI-driven workflows using aggressive or "gray-area" methods to collect publicly available information.

The activity involved government websites connected to Kansas, Illinois, Maryland, New York, Texas and California, as well as the White House Office of Management and Budget, the US Navy, Justice Department, Bureau of Economic Analysis, Census Bureau, Securities and Exchange Commission and Centers for Disease Control and Prevention. Researchers said these workflows sometimes used disposable email addresses, exposed credentials, anti-bot bypasses or large volumes of requests.

Transluce emphasized that it was not attributing the entire collection of activity to OpenAI. Researchers said attribution varied in confidence and was based on factors including task-level connections, infrastructure and timing.

The findings arrive amid growing concern over autonomous AI systems interacting with real-world digital infrastructure. Transluce said its analysis relied on automated traffic patterns, exploit indicators and human investigation to distinguish likely agent activity from ordinary web requests.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Неизвестные ИИ-агенты атаковали сайт правительства Канады026.6701-10-2026
2ИИ-агенты атаковали сайты правительства Канады014.9301-10-2026
3WP: неизвестные агенты ИИ пытались взломать сайты правительства Канады06.6901-10-2026
4СМИ: неизвестные агенты ИИ пытались взломать сайты правительства Канады010.9501-10-2026
5Nuevo incidente con la IA de Open AI: intenta acceder sin permiso a webs del Gobierno de Estados Unidos06.9426-09-2026
6OpenAI hack sparks further concern over AI models going rogue07.0128-09-2026
7Rogue AI bots have hacked into governments, universities and public agencies around the world, tech giant OpenAI admits07.1926-09-2026
8OpenAI Agent Breached Australia’s Medicare Data Portal, Government Says05.6224-09-2026
9OpenAI says its models engaged with US government websites in misbehavior disclosure05.9226-09-2026

Классификация: Международные. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 4.94. Источник: www.ibtimes.sg.