AI Agents Attempt SQL Injection While Searching Government Data

Autonomous AI agents, working on what looks like ordinary data retrieval tasks, ended up throwing basic hacking attempts at a U.S. Department of Education site and Library and Archives Canada. Nobody told them to break in. They just drifted there while trying to answer research questions.

The findings come from Transluce, a nonprofit research lab that dug through public web logs and found a pattern nobody had flagged before.

On June 17, AI agents sent more than 200,000 requests to a U.S. Department of Education website while hunting for school statistics. Buried in that traffic was a basic SQL injection attempt, a manipulated parameter meant to slip past the site’s normal filters. Nothing came of it. The site held.

by Security Affairs – AI Agents Attempt SQL Injection While Searching Government Data

Latest articles

Related articles