Dark Mode
Report traces AI agent activity targeting a Canadian government website

Report traces AI agent activity targeting a Canadian government website

Latest news on WhatsApp أجدد الأخبار على واتساب

 

 

A newly released report has revealed that AI agents attempted to test vulnerabilities on a Library and Archives Canada website in May and June, prompting a response from Canadian cybersecurity authorities, who say there is no indication that government systems were successfully compromised.

 

The findings were published this week by AI research organization Transluce, months after the activity itself took place. The organization reported the incident to the Canadian government on September 28, bringing fresh attention to the use of increasingly autonomous AI systems on public-sector websites.

 

According to the researchers, the activity occurred on May 28 and June 9, 2026, when 899 requests were directed at a Library and Archives Canada search service while an AI system was gathering historical information related to Canadian divorce records from 1905 to 1911.

 

Among those requests, researchers identified 13 attempts that resembled common vulnerability-testing techniques, including SQL injection-style activity, unusual input manipulation, efforts to alter output formats and attempts to trigger debugging functions.

 

Transluce said the available evidence suggests the attempts were unsuccessful and did not result in access to information beyond what was already publicly available.

 

The Canadian Centre for Cyber Security confirmed that it was aware of reports involving suspicious activity, including possible AI-agent activity, targeting publicly accessible Government of Canada websites.

 

The agency said there were no current indications that government systems had been compromised, noting that public websites regularly receive automated and potentially malicious requests and that such activity does not, by itself, confirm a successful cyber incident.

 

Transluce did not conclusively attribute the Canadian activity to any particular AI company. Researchers said some of the techniques resembled behaviour they had previously associated with AI agents linked to OpenAI during the same period, but stressed that they could not attribute the Canadian attempts to OpenAI with sufficient confidence.

 

The Canadian case was disclosed as part of a broader investigation into AI agents using unexpected methods while navigating government websites, adding to growing scrutiny over how autonomous AI systems behave when carrying out tasks online.