
A Government of Canada sign sits in front of a Library and Archives Canada building next to Parliament Hill in Ottawa on November 25, 2014. The Canadian Press/Adrian Wyld
The Canadian government says there are no signs of system compromise following automated hacking attempts by what appear to be AI-powered agents against a federal website.
A report published by American AI research firm Transluce indicated Library and Archives Canada was targeted in two separate incidents earlier this year, from May 28 to June 9.
The attempts employed tactics “consistent with prior observed agent activity that we have attributed to OpenAI in a similar timeframe,” said Transluce, a non-profit artificial intelligence research laboratory in San Francisco.
An OpenAI spokesperson said the company was “aware of reports of OpenAI models attempting to access publicly available information from Canadian government websites.”
A spokesperson said OpenAI was reviewing the reported findings and had provided an initial briefing to Canadian officials conducting the government’s review.
Transluce said it reported the activity to the federal government on Sept. 28.
The Canadian Centre for Cyber Security issued a public statement in response to the report the following day.
“There is no indication that government systems have been compromised at this time,” the security agency said. “Public-facing government websites routinely receive automated and potentially malicious requests. Such activity is an ongoing feature of the online environment and does not, on its own, indicate a successful cyber incident.”
The Cyber Centre said it has “robust, layered cyber security measures” in place to help protect Government of Canada networks, systems and information from “evolving” cyber threats and malicious activity.
In this case, the malicious activity came in the form of 899 incoming requests directed at the Library and Archives Canada’s “collection-search” service.
Transluce reported that arquivo.pt, Portugal’s web archive managed by the Portuguese Foundation for Science and Technology, identified 899 requests spanning May 28 through June 9.
These queries focused specifically on accessing historical information regarding Canadian divorce records spanning the period from 1905 through 1911.
The majority of requests focused on data extraction techniques, though 13 of them contained deliberate “attack payloads”—such as SQL injections and system debug toggles—intended to test the website for technical vulnerabilities defences.
“We do not believe that these probes were successful,” Transluce said. “Each one came back as a normal HTTP 200 with an empty record page, with nothing to indicate the database acted on the input or that any extra data was returned.”
AI Concerns
Artificial intelligence executives, including Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman, told the United Nations Security Council on Sept. 23 that increasingly powerful AI poses serious imminent risks if not properly managed and called for governments to work together to address those risks.
Amodei told the 15-member council that no single nation, company, or leader can manage advanced AI alone, warning that systems could soon self-improve and slip past human control.
Transluce’s report also detailed several U.S. state and federal websites that were targeted with “aggressive or gray-area techniques to retrieve information.”
Some of those sites included the U.S. Navy, the Justice Department, the U.S. Securities and Exchange Commission, and the Centers for Disease Control and Prevention.
Transluce said the attacks included techniques such as making accounts with disposable email addresses, reusing exposed credentials, bypassing antibot controls, and flooding websites with requests.
Reuters contributed to this report.











English (US) ·
Turkish (TR) ·