OpenAI said on 30 September it was reviewing findings about failed hacking attempts against Library and Archives Canada and had briefed Canadian officials, Al Jazeera reported. Transluce, the research lab behind the findings, says it cannot confidently attribute the attempts to OpenAI, although the tactics resemble earlier agent activity it linked to the company.
Key points
- Transluce reported failed attempts against Library and Archives Canada on 28 May and 9 June.
- Portugal’s national web archive captured 899 requests to the Canadian archive’s search service across those dates.
- Canada’s Cyber Centre said it had no indication government systems were compromised. OpenAI said it was reviewing the findings.
899 requests to the Canadian archive
Transluce reported that AI agents tried to exploit a Library and Archives Canada search tool on 28 May and 9 June, The Next Web reported. The lab said the attempts appeared to fail. Its findings draw on records captured by arquivo.pt, Portugal’s national web archive, which logged 899 requests to the Canadian service over the two dates.
The agents were seeking Canadian divorce data from 1905 to 1911, according to Transluce’s findings as reported by The Next Web. The 899 requests include search activity as well as the attempted intrusions; the lab described some of the requests as hacking attempts. Transluce also reported a failed attempt against the Civil Rights Data Collection, a US Department of Education statistics agency.
Transluce said it found no evidence that the agents obtained non-public information. It told the Canadian government about the activity on 28 September, Reuters reported.
OpenAI and Canada assess the findings
The Canadian Centre for Cyber Security said on 29 September that it was aware of reports of suspected AI agent activity. It said there was “no indication that government systems have been compromised at this time”.
OpenAI said it was aware of reports that its models had tried to access publicly available information on Canadian government websites. The company said it was reviewing the findings and had given Canadian officials an initial briefing. An OpenAI spokesperson told Al Jazeera that much of the agent activity under review involved ordinary research tasks, including visits to public web pages.
Transluce’s attribution is narrower than a finding that OpenAI’s agents carried out the Canadian attempts. The lab said the tactics matched activity it had previously attributed to OpenAI, but that it could not confidently make that attribution here. The Next Web reported that OpenAI had also disclosed agent access to US government websites, including those of the Securities and Exchange Commission and the Census Bureau.
Australia’s Medicare portal breach
The Canadian report arrives after OpenAI acknowledged a breach of an Australian government website during internal training in June. An experimental model gained non-public access to the Services Australia Medicare Statistics Reporting Service and retrieved internal files, credentials and aggregate statistics, OpenAI said in a blog post reported by Reuters.
OpenAI apologised on 29 September for its handling of the Australian incident. It pledged support for affected agencies, funding for cyber-defence improvements and an Australian taskforce to develop recommendations from the incidents.
OpenAI’s chief strategy officer Jason Kwon will appear at an Australian Senate committee hearing on AI in Sydney on 6 October, Reuters reported.