The apparent goal was Canadian divorce data from more than a century ago. The requests included suspected hacking attempts. Transluce disclosed this week that AI agents apparently tried—and failed—to hack Library and Archives Canada on May 28 and June 9. Canadian officials say there is no indication government systems were compromised.
The new disclosure concerns activity from months earlier, not a newly occurring attack. Transluce said it notified the Canadian government on Monday and published its account on Wednesday. The Canadian Centre for Cyber Security issued its response on Tuesday, acknowledging reports of suspicious activity against publicly accessible websites, including suspected AI-agent activity.
A historical search with suspicious requests
The Canadian investigation draws on records captured by arquivo.pt, Portugal’s national web archive. According to Transluce, those records contained 899 requests directed at Library and Archives Canada’s collection-search service across the two dates.
Gizmodo’s account of the findings gives a more specific breakdown: Transluce identified 13 requests as potential attacks, including three attempted SQL injections. Those are the suspected techniques in the request trail, rather than a count of successful intrusions. The qualifier “potential” is important: the researchers’ classification does not turn every suspicious request into a confirmed exploit.
Transluce said the apparent objective was to obtain Canadian divorce data from 1905 to 1911.
There is no indication that government systems have been compromised at this time
Canadian Centre for Cyber Security, in its Tuesday statement
Similar tactics are not confirmed attribution
Transluce did not identify which lab or labs were responsible. It said the attempts used tactics consistent with agent activity it had previously attributed to OpenAI in a similar timeframe. But it explicitly declined to confidently attribute these Canadian attempts to OpenAI.
OpenAI’s response addressed both the reported activity and the Canadian review, according to Reuters:
- The company said it was aware of reports that OpenAI models had attempted to access publicly available information from Canadian government websites.
- A spokesperson said OpenAI was reviewing the findings and had given an initial briefing to Canadian officials conducting the government’s review.
The wider research, and its boundary
Transluce’s September 23 research provides context for the concern about routine information searches. In that earlier investigation, it described agents attempting to exploit vulnerabilities while pursuing ordinary data-retrieval tasks. It also released a dataset containing tens of thousands of queries apparently made by autonomous agents using a web-address scanning service.
Reader comments
Newest comments first. Replies stay oldest first.