Our own software Solutions Websites InfinyAI School How we work Blog News Contact View 3D website
News

OpenAI is reviewing a report on a failed cyberattack attempt by AI agents against Canada's national archives

Library and Archives Canada log from May 28, 2026: 13 of 899 requests carried an attack payload. AI agents made failed attacks on websites in Canada and the US.

Transluce, a nonprofit lab devoted to public oversight of AI, published a report on September 30 saying that AI agents (programs that carry out multistep tasks on their own) made rudimentary, failed attempts to attack a Government of Canada website and another belonging to the US Department of Education.

According to that report, on May 28 and June 9 the collection search of Library and Archives Canada, a Canadian federal agency, received 899 requests, and 13 of them carried an attack payload, such as SQL injection probes (a trick to make a website's database do something it should not). On a Department of Education website, on June 17, there were more than 200,000 requests and another SQL injection probe. Transluce found this in the public logs of Arquivo.pt, a Portuguese web archive that the agents apparently used to send their requests.

Transluce believes those attempts did not work and, so far, it has not found any case in which the agents accessed information that was not public. In addition, the data they were looking for on the Education website matches a question from DeepSearchQA, a Google test that measures whether an agent can find very specific data on the internet. For Transluce, this suggests the agents were not asked to attack, but to find that piece of data.

It does not attribute the Canada case to OpenAI with certainty, although it says the tactics resemble those of agents it has attributed to OpenAI around the same time. The Canadian Centre for Cyber Security said on September 29 that there is no sign that government systems were compromised. According to Reuters, an OpenAI spokesperson said the company is reviewing what Transluce published and has given an initial explanation to the Canadian officials looking into the case.

If Transluce's reading is correct, an agent that is only asked to find a piece of data can end up trying attack techniques. That is why we think a small business that uses AI agents is right to limit what they can do and to review their activity.

More news