Canada

AI hack on Canadian archive is ‘the world we live in now,’ expert warns

Published: 

The Library and Archives Canada website, which AI agents tried to hack in May and June, according to research firm Transluce. (CTV News)

TORONTO — Artificial intelligence agents apparently searching for century-old divorce records tried to hack a federal government website this spring, according to an AI research firm. Canada’s cybersecurity agency says there is no indication any government systems were compromised.

San Francisco-based non-profit Transluce says AI agents, which can carry out tasks on their own, targeted the Library and Archives Canada website on May 28 and June 9. They appear to have been trying to dig up divorce records between 1905 and 1911.

The Library and Archives Canada The Library and Archives Canada website, which AI agents tried to hack in May and June, according to research firm Transluce. (CTV News)

Of the nearly 900 requests captured by a Portuguese web archive, Transluce says 13 “carried attack payloads rather than ordinary queries.”

Those included SQL injection probes, a basic hacking technique that involves entering database commands into a search box in the hope the system will carry them out.

It’s not entirely clear which AI was used, or what exactly it was asked to accomplish. But Transluce says the tactics resemble those of agents it previously linked to OpenAI during the same period, though it stopped short of blaming the company.

In a statement, OpenAI said, “We’re reviewing these findings and have provided an initial briefing to Canadian officials conducting the government’s review.”

Mark Daley, chief AI officer at Western University in London, Ont., said the agent likely was not trying to cause harm.

“The agent is just like, ‘I have a job. I’m going to try to do the job,’” Daley told CTV News.

“It went beyond just a public search and tried to hack the website so it could get the information it wanted, but it wasn’t successful.”

Daley said that is what sets the agent’s behaviour apart from that of a normal person.

“A human would stop at the point where they couldn’t get that information. They wouldn’t try to hack the website,” he said. “The agent decided that the next most obvious thing to do is to hack the website.”

Mark Daley Mark Daley, chief AI officer at Western University. (CTV News)

The Canadian Centre for Cyber Security said it is assessing the information. “There is no indication that government systems have been compromised at this time.”

It noted that public-facing government websites routinely receive automated and potentially malicious requests, which on their own do not indicate a successful cyber incident.

Canada’s AI minister, Evan Solomon, said Ottawa is still assessing what happened and promised to keep Canadians informed.

AI companies largely left to police themselves

The findings follow reports of AI agents unexpectedly breaching government and corporate systems. Australia recently said an OpenAI agent hacked into a government health data portal in June and accessed files. OpenAI apologized on Tuesday.

It also comes as AI companies are largely left to police themselves. Leaders of the biggest firms met with U.S. President Donald Trump at the White House this week and signed a voluntary accord on AI safety. Trump has refused to impose strict rules on the industry, saying they could help China win the AI race.

Daley believes rogue AI incidents now number in the hundreds “and probably that’s the tip of a very large iceberg.”

He said this was the first attempt on a Canadian government website he had heard of, but added: “I certainly anticipate we’ll be hearing a lot more of this in the future.”

“This is the world we live in now,” Daley said, “and there’s no going back.”