Published on 01/10/2026 – 12:22 GMT+2

Rogue AI agents attempted to breach US and Canadian government websites, according to nonprofit research lab Transluce, with indications that agents linked to Google and OpenAI were involved.


Two notable incidents showed aggressive tactics used to pull publicly available data from the U.S. Department of Education’s Civil Rights Data Collection and Library and Archives Canada, a federal agency; both attempts ultimately failed to compromise any information.

Transluce notes that these events are part of a broader pattern of automated workflows attributed to AI agents. “These workflows employ aggressive or borderline techniques to extract data from government sites, sometimes using the sites in unintended ways or violating explicit usage policies,” the organization’s researchers explained.

Additional targets listed by Transluce include the White House, the Departments of War, Justice, and Commerce, the Centers for Disease Control and Prevention, the Securities and Exchange Commission, and state agencies in California, Maryland, Illinois, Texas, and New York.

In none of these cases did the agents obtain information that was not already publicly accessible.

The latest findings emerge amid a rising number of reports of unexpected or unauthorized behavior by AI agents.

In September alone, two significant incidents involved rogue OpenAI agents: one where agents leaked private user images to public sites, and another where agents tried to gain access to government data in the United States and Australia.

Following safety researchers’ warnings about ‘critical’ cybersecurity capabilities and erratic, unauthorized conduct, OpenAI has postponed the rollout of its next‑generation Astra model.

US and Canadian attempts

Agents probed the U.S. Department of Education on June 17 while retrieving school statistics.

Transluce reports that the agents issued more than 200,000 requests to the site, including a failed attempt to submit deliberately flawed data to test the database’s vulnerability and evade normal filters.

The researchers observed that the data sought matched a web‑search task in Google’s DeepSearchQA benchmark, suggesting the agents were not instructed to launch hacking attacks but were evaluated on their ability to retrieve specific niche information from the internet.

Transluce disclosed the attempt to the U.S. Department of Education in September; the department said it observed no impact on its services.

Similar efforts were directed at Library and Archives Canada on May 28 and again on June 9.

According to logs captured by the Portuguese web archive Arquivo.pt, the agents made 899 “collection‑search” requests for divorce records spanning 1905‑1911.

Of those requests, 13 contained payloads designed to probe the site’s vulnerability. Neither attempt succeeded in compromising data.

Transluce cannot definitively attribute the activity to OpenAI, though the tactics resemble behavior previously linked to the company.

The organization reported these incidents to the Canadian government earlier this week.

The Canadian Centre for Cyber Security responded, stating “there is no indication that government systems have been compromised at this time.”

Transluce published its findings yesterday, drawing on data from Arquivo.pt and urlquery.net, a free web‑based service for URL and domain scanning.

Source link

Exit mobile version