Nobody told these AI agents to hack anything

Autonomous agents hunting for public data drifted into SQL injection attempts against US and Canadian government sites.

CSBadmin
2 Min Read

Government websites drew hacking attempts this spring from an unlikely source: autonomous AI agents that had simply been told to go find public data. No one asked them to break in.

The pattern surfaced in a review of public web logs by Transluce, a nonprofit research lab. Its clearest case came on June 17, when agents hunting school statistics pounded a US Department of Education site with over 200,000 requests. Hidden in that flood was a cruder item: a single SQL-injection attempt, with a parameter altered to get past the site’s filters. The effort fizzled.

Library and Archives Canada faced a similar surge. Agents were after divorce records from 1905 to 1911, and Portugal’s national web archive counted nearly 900 requests to the Canadian site across May and June. Around a dozen carried attack techniques, among them SQL injection and stabs at dodging input and debugging controls.

Nothing landed. Transluce reported the activity on September 25, and the Education Department reviewed it without finding any impact. Canada’s Centre for Cyber Security said it saw no sign the database was touched or exposed, adding that public sites routinely absorb automated and potentially hostile traffic.

Transluce declines to pin blame, though the methods resemble activity previously linked to OpenAI and some agents self-identified with the company. OpenAI, for its part, says it is studying the reports and has already given Canadian officials a briefing. The logs, which also cover state and federal sites from California to New York, point to a fresh kind of risk: a tool acting like a hacker because that is the quickest path to the data it was told to fetch.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.