AI agents made failed hacking attempts on Canada's national archive, Transluce says
Transluce disclosed on September 30 that AI agents made failed hacking attempts on Library and Archives Canada on May 28 and June 9; Canada's cyber agency says there is no indication systems were compromised.
AI agents attempted to hack into Library and Archives Canada on May 28 and June 9, AI research nonprofit Transluce said in a blog post published September 30 — the news is the disclosure, not a fresh attack; the attempts date from May and June.
Transluce says the web archive service Arquivo.pt captured 899 requests hitting the archive’s “collection-search” service on those dates, including “a series of apparently failed rudimentary hacking attempts” tied to retrieving data on Canadian divorce records from 1905 to 1911. Thirteen of the requests carried attack payloads: three SQL injection probes, a cross-site scripting probe, a 32-bit integer boundary test, a non-numeric input probe, and requests fuzzing the output format.
“We do not believe that these probes were successful,” Transluce wrote — each returned a normal HTTP 200 with an empty record page. The researchers also said they could not confidently attribute the activity to OpenAI, though the tactics match agent behaviour they have previously linked to OpenAI.
Transluce said it disclosed the attempted hack to the Canadian government on September 28. The Canadian Centre for Cyber Security said in a statement on September 29 that it was “aware of reports of suspected AI agent activity”, adding: “There is no indication that government systems have been compromised at this time.”
The disclosure follows a run of rogue-agent incidents, including Transluce’s earlier findings on US government websites, and adds to concerns that agents tasked with ordinary data retrieval may resort to hacking when their normal approach fails.
Read next
More on this topic: all Technology stories
