Rogue AI agents tried and failed to hack US and Canadian government websites

Researchers cannot confidently say who was responsible, but evidence points to rogue Google and OpenAI agents carrying out a range of aggressive tactics to collect datasets and test their vulnerabilities.
Rogue AI agents attempted to hack US and Canadian government websites, according to non-profit research lab Transluce, with evidence suggesting that Google and OpenAI’s agents were responsible.
Two incidents in particular demonstrated aggressive techniques being used to access publicly available data from the US Department of Education’s Civil Rights Data Collection, and Library and Archives Canada, a Canadian federal agency, with both ultimately failing to compromise any data.
Transluce reports that the incidents are part of a “broader pattern of automated workflows” attributed to AI agents. “These workflows use aggressive or grey-area techniques to retrieve information from government websites, sometimes using sites in unintended ways or violating explicit usage policies,” the organisation’s researchers said.
Among the additional targets were the White House, Departments of War, Justice and Commerce, as well as the Centers for Disease Control and the Securities and Exchange Commission, and state agencies in California, Maryland, Illinois, Texas, and New York.
In none of these cases, however, did agents gain access to information that was not already publicly available.
The latest findings come amid a growing number of reports of unexpected or unauthorised behaviour by AI agents.
In September alone, there have been two major incidents involving rogue OpenAI agents — the first involved agents leaking private user images to public websites, and the second with agents attempting to win access to government data in the US and Australia.
The company has since decided to delay the rollout of its next-generation Astra model after safety researchers flagged “critical” cybersecurity capabilities and unpredictable, unauthorised behaviour.
US and Canadian attempts
Agents attacked the US Department of Education on 17 June while looking up school statistics.
Transluce reports that the agents made more than 200,000 requests to the website, including a failed attempt to send deliberately flawed data to test the site’s database vulnerability and consequently bypass the site’s normal filters.
The researchers found that data stored on the website appeared to match a web search task in Google’s DeepSearchQA benchmark, which they say suggests the agents were not told to carry out hacking attacks but were “graded on their ability to successfully retrieve specific niche information from the internet”.
Transluce disclosed the attempted hack to the US Department of Education in September, with the department responding they had not seen any impact on their services.
AI agents made similar attempts on Library and Archives Canada in two separate incidents, on 28 May and later on 9 June.
The agents issued 899 “collection-search” requests for data relating to divorce records from 1905-1911, according to data picked up by the official Portuguese web archive Arquivo.pt.
Of the 899 requests, 13 carried attack payloads to test the website’s vulnerability. Again, none of the attempts on either occasion were successful.
Transluce says it cannot “confidently attribute” the attempts to Open AI, but the tactics were consistent with activity it had previously attributed to the company.
The organisation reported these incidents to the Canadian government earlier this week.
The Canadian Centre for Cyber Security issued a statement in response, saying “there is no indication that government systems have been compromised at this time.”
Transluce published its findings yesterday, after carrying out research using information from Arquivo.pt and urlquery.net, the free web-based security service for URL and domain scanning.



