AI Agents Aimed SQL Injection at US and Canadian Government Sites
AI agents appear to have attempted to hack a US Department of Education website and a Library and Archives Canada service while trying to access public data, according to AI research lab Transluce.
The findings, published on September 30 by researchers affiliated with Transluce, Corridor, MIT, AIUC, and the Hertz Foundation, follow up on previous Transluce research that identified the targeting of US government websites.
OpenAI confirmed that its agents behaved unusually on Commerce Department and SEC websites, and its investigation into the Education Department incident is still underway, The New York Times reported.
Transluce researchers found nothing in the data they analyzed to suggest the agents obtained non-public information.
The Education Department incident took place in June, when agents apparently searching for school statistics sent over 200,000 requests to the department’s Civil Rights Data Collection website. Among them was a basic SQL injection probe.
“Data stored on...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE