Foreign Affairs

AI Agents Tried To Hack Canadian National Archives Website, Researchers Say

AI Agents Tried To Hack Canadian National Archives Website, Researchers Say

Rinbro, CC0, via Wikimedia Commons

The list of governments targeted by artificial intelligence agents appears to be growing and now may include the U.S.’ northern neighbor, researchers say.

AI agents made hacking attempts against Library and Archives Canada’s (LAC) website on May 28 and June 9, San Francisco-based AI research lab Transluce said in a Wednesday report. Though Transluce did not blame OpenAI for the attempts, the lab said the agents used the same kinds of tactics it had already tied to OpenAI on U.S. government websites.

“We do not confidently attribute these attempts to OpenAI, but they exhibit tactics consistent with prior observed agent activity that we have attributed to OpenAI in a similar timeframe, including the use of Arquivo.pt [a Portuguese web archive], conducting aggressive data collection focused on targeted, obscure information, and probing for cybersecurity vulnerabilities,” Transluce said in its report.

The report follows a string of incidents involving OpenAI’s agents, including a breach of an Australian government healthcare portal that Australian officials announced Sept. 24 and probes of U.S. federal agencies’ websites that OpenAI disclosed Sept. 25. 

“We are aware of reports identifying suspicious activity, including suspected AI agent activity, targeting publicly accessible websites, such as the Government of Canada,”the Canadian Centre for Cyber Security said in a Tuesday statement. “There is no indication that government systems have been compromised at this time.”

OpenAI said it was “aware of reports of OpenAI models attempting to access publicly available information from Canadian government websites,” the tech giant told Reuters. Canadian officials investigating the activity have already received a briefing from OpenAI, which is looking into the findings, a company spokesperson added.

The agents sent 899 requests to the agency’s search tool on those two dates while looking for Canadian divorce records from 1905 to 1911, according to Transluce’s report. Thirteen of those requests tried to trick the LAC site into returning data it would not normally show.

“We do not believe that these probes were successful,” Transluce said, adding that nothing indicated “the database acted on the input or that any extra data was returned.”

The research lab said it notified the Canadian government of the activity on Monday.

The Communications Security Establishment (CSE), which oversees the Canadian Centre for Cyber Security, told the Daily Caller News Foundation it is “working closely with government and industry partners to assess the information referenced in the reports,” but declined to comment further on the specific details of the incident.

The agency said frontier AI “is also being used by cyber threat actors to increase the speed, scale, and sophistication of malicious activity,” and that AI agents’ ability to act on their own “can introduce significant security risks.”

Library and Archives Canada referred the DCNF to the CSE’s statement but declined to comment further.

OpenAI did not immediately respond to the DCNF’s request for comment.

Agents sent more than 200,000 requests to a U.S. Department of Education website on June 17 while searching for school statistics, including one failed attempt to trick the site’s database, according to the report.

Transluce also documented agents probing other government websites, such as the Justice Department, the Navy and several states.

“This failed attempt connects to additional rogue activity, some of which is not clearly attributable to OpenAI, where agents used an array of gray-area tactics to probe U.S. Government websites, often using sites in unintended ways and sometimes violating explicit usage policies across targets,” a Transluce spokesperson told the DCNF.

The U.S. Department of Commerce’s economic data was another target on June 18, when an automated program tried to sign up for access under the name “OpenAI Research” using a throwaway email address, the report stated.

Republican Sen. Josh Hawley of Missouri chaired a Senate hearing on rogue AI agents Wednesday, where he said OpenAI CEO Sam Altman declined to attend and testify.

Hawley opened an investigation into OpenAI on Sept. 10 after its agents breached New York-based open-weight AI platform Hugging Face in July.

All content created by the Daily Caller News Foundation, an independent and nonpartisan newswire service, is available without charge to any legitimate news publisher that can provide a large audience. All republished articles must include our logo, our reporter’s byline and their DCNF affiliation. For any questions about our guidelines or partnering with us, please contact [email protected].