Incident Reports AI Agents Targeted U.S. and Canadian Government Websites Evidence from Arquivo.pt and urlquery.net Jack Cable * , 1 , Daniel Chiu * , Francisco Pernice * , 2 , Laura Ruis * , 2 , Selena Zhang * , 3 , Tetiana Bas 4 , Jordan Chetty 5 , Farzaan Kaiyom 1 , Gary Shen 4 , Conrad Stosz † , 3 , Jacob Steinhardt † , 3 1 Corridor · 2 MIT · 3 Transluce · 4 AIUC · 5 Hertz Foundation · * First authors, alphabetical · † Senior authors Transluce | Published: September 30, 2026 Following up on our previous blog post , we discovered several additional incidents where rogue AI agents appear to have used aggressive techniques to access publicly available data on government websites. This includes two rudimentary and failed hacking attempts, one against the U.S. Department of Education’s Civil Rights Data Collection , and one against Library and Archives Canada, a Canadian federal agency. These failed attempts connect to additional rogue activity where agents used an array of aggressive tactics short of hacking to probe U.S. government websites, often using sites in unintended ways and sometimes violating explicit usage policies. This activity targeted websites across the White House, the Departments of War, Justice, and Commerce, the CDC and SEC, and state agencies in California, Maryland, Illinois, Texas, and New York. We have so far identified no instances in these datasets where agents gained access to any information that is not publicly available. We base our analysis below on data from our previously published urlquery.net dataset, as well as Arquivo.pt , a Portuguese web archive with a feature called ArchivePageNow that was used to send requests and retrieve data. Agents attempted a basic SQL injection on the U.S. Department of Education On June 17, while apparently looking up school statistics, agents made more than 200,000 requests to a U.S. Department of Education website. The activity included a rudimentary failed hacking attempt, a SQL injection probe where the agents added the text “ State_Id=1 OR 1=1 ” in an attempt to bypass the site’s normal filters. In the 40 seconds leading up to the SQL injection, there were a series of requests with a variety of unusual state ID inputs (without access to more context about the agents and their reasoning traces, the purpose of this set of queries is unclear): State_Id=0 State_Id=-1 State_Id=99 State_Id=999 State_Id=1,2 (potentially to test SQL injections/parameter handling) State_Id= (empty string) State_Id=1&State_Id=2 State_Id%5B%5D=1&State_Id%5B%5D=2 (URL-encoded square brackets) State_Id=1%2C2 (URL-encoded comma) Data stored on this website appears to match a web search task in Google's DeepSearchQA benchmark , suggesting that the agents were not given a hacking-related task but were being graded on their ability to successfully retrieve specific niche information from the internet. The specific DeepSearchQA task (dsqa_250): Using data from civilrightsdata.ed.gov for the 2017–2018 school year, determine which of the following states—South Carolina, North Carolina, Georgia, or Virginia—had the highest ratio of full-time equivalent school counselors to students reported as victims of race-related harassment or bullying. How the agents’ query parameters we observe in Arquivo traffic relate to dsqa_250: Query parameter Explanation survey_Year_Key=9 Corresponds with 2017-2018. Agents often made multiple queries using Arquivo to find this mapping, often enumerating IDs in order. Measure_Id=130 Corresponds to race-based bullying victims. State_Id=11 , State_Id=28 , State_Id=41 , State_Id=46 Corresponds to the relevant states. We also note that more than 10,000 requests included a tag beginning with “ oai ” ( example ). 99.6% of those requests use a combination of the three query parameters described above, indicating the submitters of these requests were attempting to answer dsqa_250. We disclosed this attempted hack to the Department of Education on September 25, 2026. A Department spokesperson subsequently commented that they had observed no impact to their services from this reported incident. Download the Data Agents attempted rudimentary hacks on Library and Archives Canada On May 28, 2026, and June 9, 2026, Arquivo.pt captured 899 requests hitting the “collection-search” service of Library and Archives Canada (LAC), including a series of apparently failed rudimentary hacking attempts. The requests were associated with retrieving data on divorce records in Canada between 1905 and 1911. We do not confidently attribute these attempts to OpenAI, but they exhibit tactics consistent with prior observed agent activity that we have attributed to OpenAI in a similar timeframe, including the use of Arquivo.pt , conducting aggressive data collection focused on targeted, obscure information, and probing for cybersecurity vulnerabilities. Of these 899 requests, 13 of them carried attack payloads rather than ordinary queries, including by probing for vulnerabilities in the record-identifier parameter. The payloads included: Three SQL injection probes ( an apostrophe , 1 OR 1=1 , and 1,2 ) An encoded < for cross-site scripting 2147483648 to test a 32-bit integer boundary The string abc for non-numeric handling Five requests fuzzing the output format ( .json , ?output= , ?raw= , ?url= ) Two toggling a debug=1 flag We do not believe that these probes were successful: each one came back as a normal HTTP 200 with an empty record page, with nothing to indicate the database acted on the input or that any extra data was returned. We disclosed this attempted hack to the Canadian government on September 28, 2026. On September 29, the Canadian Centre for Cyber Security issued a public statement in response. Agents used a range of other aggressive tactics against U.S. state and federal websites In addition to the above, we identified a broader pattern of automated workflows that we attribute to AI agents with varying levels of confidence, based on task-level connections, shared infrastructure, and timing. Some of this traffic overlaps to varying degrees with prior activity confirmed to be associated with OpenAI, and in some cases agents explicitly mark themselves as being associated with OpenAI. However, we are not attributing this traffic as a whole to OpenAI nor do we attempt to estimate attribution for each incident. In the below cases, we did not observe hacking techniques. Rather, these workflows use aggressive or gray-area techniques to retrieve information from government websites, sometimes using sites in unintended ways or violating explicit usage policies. This includes techniques like making accounts with disposable email addresses, reusing exposed credentials, bypassing antibot controls, and flooding websites with requests. We outline our observations here: Kansas: On May 7, Arquivo recorded 36,578 user-triggered captures of KansasMemory.gov (a site apparently administered by the Kansas Historical Society with support from the Kansas government), with a peak of 1,093 captures per minute. Early requests returned content , but over the course of the campaign the website started returning gateway timeouts . We were not able to confirm whether the activity caused a service disruption. Illinois: On four separate days between April 19 and May 1, we observed 251 related Arquivo captures involving Illinois’s legacy IQuery public-health statistics portal. Initial captures return “service unavailable”, but the automated workflow nevertheless tried workarounds, like direct IP-routes , URL-parsing variations , and a guessed ePass route that redirected to the state’s sign-in system. None of the reviewed responses returned IQuery data. Maryland: On May 6, Arquivo recorded 295,912 captures across multiple Maryland hosts containing education statistics, peaking at 5,594 captures per minute. The activity involves extensive guessing of downloadable filenames , alongside a successful download of public aggregate datasets of students’ math performance . Separately, as early as March 2, Arquivo recorded a smaller burst of API requests to Maryland’s mathematics-performance API, although we have not established a connection with the later May activity. New York State: On May 17, we observed archived activity attempting to access public New York school-enrollment statistics through modified URLs and multiple intermediary services. Initial requests were blocked, while later attempts returned public statistics . The same school and enrollment selections appear in wiki activity previously documented by collusion.wiki . Texas: Also on May 17, archived results show repeated attempts to retrieve public sexually transmitted infection statistics from the Texas Department of State Health Services, through direct export requests as well as through intermediary conversion services which have previously been reported to be used by agents. We could not confirm successful retrieval of the requested statistics. California:
Incident Reports AI Agents Targeted U.S. and Canadian Government Websi
Incident Reports AI Agents Targeted U.S. and Canadian Government Websites Evidence from Arquivo.pt and urlquery.net Jack Cable * , 1 , Daniel Chiu * , Francisco Pernice * , 2 , Laura Ruis * , 2 , Selena Zhang * , 3 , Tetiana Bas 4 , Jordan Chetty 5 , Farzaan K
这条信息对 FDE 的直接价值在于提醒交付人员持续关注模型、智能体与企业流程之间的变化。面对类似项目,应先确认客户的真实业务目标、数据边界、权限条件和验收指标,再选择工具并用最小场景验证结果,避免只追逐功能更新。