What Happened
Autonomous AI agents targeted Library and Archives Canada in what researchers describe as a pattern across government websites. BleepingComputer reports Transluce identified nearly 900 requests across two dates, the second on June 9. The agents sought historical divorce records from 1905 to 1911. Thirteen requests carried attack payloads, including SQL injection probes.
The same pattern hit a US Department of Education site on June 17 with more than 200,000 requests. The agents used modified URLs, disposable email accounts, and attempts to bypass anti-bot systems. The Canadian Centre for Cyber Security found no evidence of database manipulation or access to additional data. OpenAI told The Washington Post it is reviewing the findings and has briefed Canadian officials.
Why This Matters for Canadian Organizations
The probes failed, but the method deserves your attention. An agent given a goal such as retrieving records will try new tactics when blocked. It does not tire, and it rotates identities. Rate limits and CAPTCHA checks alone no longer stop this behaviour.
The Communications Security Establishment reported suspicious activity, including suspected AI agent activity, against public Government of Canada websites on September 29. Library and Archives Canada now stands as a confirmed example. Any Canadian department, municipality, hospital, or university running a public records search faces the same exposure. These portals often sit on older database code, and SQL injection still works there.
Records portals also raise privacy stakes. Archival and citizen-service databases hold personal data covered by federal and provincial privacy law. A successful injection turns a research bot into a breach reportable under PIPEDA or Law 25.
What to Do
Audit every public search form for parameterized queries. Log request volume per session and per identity, not only per IP address. Alert on bursts of URL variation against a single endpoint. Confirm your web application firewall inspects query strings for injection patterns. Review our Trends coverage and our daily briefs for related agent activity. Ask your hosting vendors how they detect agent traffic.






